soldi build log

Daily ledger of vertical slices shipped toward the PRD MVP. Each entry is the slice that landed, the verification evidence, and what's queued next.

2026-06-01 direction change: adopting the closer — v2 prototype design system and expanding scope to Comps + Pipeline + Sequences. See docs/ROADMAP.md, docs/DESIGN_SYSTEM.md, and docs/SPEC_{COMPS,PIPELINE,SEQUENCES}.md. Next build slice is the design-system migration (foundation), then the 3 new pages. Historical only: Zak's pinned July 13 v60 mock and July 15 parity checklist supersede that buyer-surface direction for the MVP.


2026-07-26 — Systemic responsive pass merged and hosted-proved

  • Market, My Leads, Territories, Activity, and invoice summaries now switch from wide tables to compact cards at and below 768px; My Leads' table fills its desktop container and Billing/Activity cap at 900px on wide screens.
  • Territory bid, cap, weekly-cap, choice, and removal controls now reserve 44px. Territory and request-refund dialogs cap at 600px; the Territory sheet remains a phone-only bottom sheet below 641px.
  • The tablet shell retains its balance pill. Activity keeps details and right-aligned money in distinct grid areas. Invoice rows carry explicit mobile labels instead of forcing a 640px horizontal table.
  • True zero inventory now says New leads are on the way., explains the live shelf is empty, and links to View Territories; filtered-empty behavior still offers Clear filters.
  • Exact-hosted visual inspection of the preceding share fix caught a clipped third action despite zero document overflow. The responsive candidate places Call/Text together and gives Share its own full-width row at and below 768px.
  • The required make-it-sexy pass favored truthful hierarchy, actionable empty-state copy, and balanced controls over decorative motion. The make-it-simpler pass kept one shared 768px boundary, reused existing cards/drawers, and added no dependency or parallel component.
  • Focused proof passed 87 tests. Full root verification passed 101 app files / 926 tests, TypeScript, production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions.
  • PR #310 normally merged as exact two-parent main 2d08757e50c529a9138cd89ccf195d2e4b637743. The protected migration boundary was a no-op through 0043; exact source tree 5938674ff07894fe46b418c73783708565e13261 and assets b675c22a95e26ac8d51cbca2075e88d51013f7876d5eed15dc3072fcd2ce9741 deployed as 7a2b8c28-8c8c-4333-9e9f-f1345845ec6b / version cd72c388-bcd4-4c86-8259-f2d2804d4735.
  • The authenticated hosted matrix passed twice across five routes and 390x844, 768x1024, and 1440x900: 15 / 15 route-width rows, zero document overflow, console errors, failed application API responses, card-boundary misses, sub-44px Territory controls, ledger/invoice alignment misses, dialog width/centering failures, or Share-action clipping.
  • Visual review after animations settled confirmed the phone Share drawer, tablet Market/My Leads/Territories/Activity/Billing surfaces, and the full-width desktop My Leads table. Zak received the exact demo link for his physical-iPhone pass.

Next up: collect Zak's physical-iPhone acceptance and fix forward on any device-only finding. Production remains untouched and separately gated by live Stripe onboarding plus a freshly authorized retained-production D1 rehearsal/rollback for the exact promotion candidate. Durable receipt: artifacts/soldi-completion-2026-07/shots/responsive-hosted-receipt-2d08757-20260726.md.

2026-07-26 — Share/login stragglers merged and hosted-proved

  • PR #309 normally merged as exact main 2ea307d106e04a7a3e9785ad10f57a3c604ab130.
  • The protected staging controller found no pending migration through 0043 and deployed exact source tree 1452a8c3f6bdc7531763172ba50b1d59dc891cdf / assets f64816ebbc56bd55600acce741ab86e42d186b327cccfb7319539c19417472e7 as deployment 58500d27-e0b6-4c7c-9254-7299c9594d49 / version 2fe9909b-7eaf-42d4-bb8e-8ea64ae71703.
  • Hosted 390x844, 768x1024, and 1440x900 proof retained Forgot password, removed the logged-out protected-Market loop, and rendered owned-lead share previews as 4bd SFR; all three had no document overflow, console errors, or failed API responses.
  • Visual inspection caught one separate mobile Share-drawer clipping defect that automated document-width checks did not see. It is included in the next responsive PR rather than hidden by this receipt.

Next up: land and host-prove the responsive batch, then hand Zak the exact staging link for physical-iPhone acceptance. Production is untouched.

2026-07-26 — Share-label and logged-out navigation stragglers

  • Owned-lead share formatting now canonicalizes literal imported Sfr as SFR, matching the already-approved single_family share payload without rewriting stored lead data.
  • The logged-out login page no longer offers Back to Open Market. The Market root is protected, so that link only returned the buyer to the same authentication redirect. Forgot password remains available.
  • The make-it-sexy review found no responsible visual embellishment to add to a two-line removal/casing correction; the make-it-simpler pass confirmed that deleting the misleading link is the smallest truthful interaction.
  • Focused proof passed 10 tests. Full root verification passed 101 app files / 925 tests, TypeScript, production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. Local login rendering at 390x844, 768x900, and 1440x900 had no horizontal overflow, retained Forgot password, and had no Market-loop link.

Next up: normally merge the source PR, deploy its exact merge to protected staging, and repeat the login/share proof against the hosted Worker before handing Zak the link. Production is untouched.

2026-07-26 — M8 staging inventory restoration live and hosted-proved

  • Read-only protected-staging D1 proof found nine retained legacy staging fixture leads and thirteen attached economic references. All available inventory lacked a latest verified-consent row, so M8 correctly hid it from Market and Territory availability.
  • The existing reseed controller correctly refused to delete or replace referenced rows. A new receipt-bound m8-plan / m8-apply path instead preserves every retained wallet, purchase, refund, and portfolio row; adds four isolated example.test fixture leads; and attaches explicit synthetic staging-only consent evidence to a nine-lead QA shelf.
  • The target shelf is exactly three Cold, three Warm, and three Hot leads across four approved situations and varied ages. The controller is fixed to soldi-staging, rejects partial/colliding/economically referenced target state, uses one D1 batch, and is idempotent. Production fixture exclusion remains unchanged.
  • PR #307 normally merged as exact two-parent main 82117c664b79c02475669797d00461b3a3686108. Protected staging had no pending migration through 0043 and deployed that exact merge as version c576c94b-bd47-47c5-ae68-e5c69c07e6f4 / deployment 8901eb9f-ceb8-45d3-b917-cf1cb08aaade.
  • Receipt-bound apply/readback produced exactly nine marketable leads with a 3/3/3 Cold/Warm/Hot split, four situations, and five distinct age dates. Wallet transactions 66, purchases 27, refund requests/outcomes 7/1, and portfolios 36 were unchanged; production was not touched.
  • Hosted Market and Territories passed 390x844, 768x900, and 1440x900 with no document overflow, console errors, or failed responses. Market showed all nine Buy actions; phone controls were 44px high. The pass also confirmed the already-open systemic issue that desktop/tablet Territory steppers remain 24–30px.
  • Focused staging controls passed 67 tests / 292 assertions. Full root verification passed 101 app files / 923 tests, TypeScript, production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. Durable receipt: artifacts/soldi-completion-2026-07/shots/m8-staging-inventory-hosted-receipt-20260726.json.

Next up: land the SFR owned-share label and remove the logged-out Open Market loop, then close the six-part tablet/desktop responsive pass. Zak can resume his physical-iPhone Market/Territory pass against https://staging.soldi.cc.

2026-07-25 — Production Stripe activation blocker isolated

  • A read-only provider audit opened the Soldi Stripe account's live Workbench URL for account acct_1TtjDjPuLV917S5K. Stripe redirected it to the /test/ route, labeled the account Sandbox / Test mode, and kept live profile creation behind Verify your business.
  • The existing sandbox destination Soldi staging remains active at https://staging.soldi.cc/api/v1/webhooks/stripe with the expected three events. No provider configuration was changed.
  • Cloudflare production secret-name readback shows both STRIPE_SECRET_KEY and STRIPE_WEBHOOK_SECRET; values were never read or persisted. Public production base health returns 200, while /api/v1/health/stripe remains 404 on the legacy Worker.
  • The durable, secret-free read-only receipt is artifacts/soldi-completion-2026-07/shots/m9-production-stripe-readiness-audit-20260725.json.

Next up: Cam must complete Stripe's business verification and live-profile onboarding with the business representative, tax, and payout details. After that, configure and receipt the live Soldi webhook, statement descriptor, and receipt emails before any production promotion. Production remains HOLD.

2026-07-25 — Exact M8 staging Stripe acceptance and replay

  • A fresh non-demo staging buyer began with the normal $500 promotional signup credit, then created a genuine $1,000 Stripe-hosted Checkout against exact sandbox account acct_1TtjDjPuLV917S5K.
  • Checkout cs_test_a1PRk3fe834jgvgZUjZgKhd5r61nevObzYueMCdEtjokrtfZpYyEBHE3oE, PaymentIntent pi_3TwzX7PuLV917S5K0IErxjpN, and signed event evt_1TwzX9PuLV917S5KjpxoMvik bind the payment to exact staged application 1c142547, assets 57efda7c…, Worker 6fba2fcd…, and deployment ca805c8b….
  • The signed webhook created one immutable stripe_verified_funding wallet row for exactly 100000 purchased cents. The buyer moved from total/promotional/purchased 50000/50000/0 to 150000/50000/100000, with no bonus or hold.
  • An explicit Stripe Workbench resend reached https://staging.soldi.cc/api/v1/webhooks/stripe; exact Worker 6fba2fcd… returned 200. Post-replay D1 still contained one processed event, one economic claim, one funding-evidence row, and one $1,000 Stripe ledger row. No secret or raw signed payload was persisted.
  • The closed schema-1 receipt is artifacts/soldi-completion-2026-07/shots/m8-stripe-acceptance-20260725.json.

Next up: obtain Zak's physical-iPhone pass, run a freshly authorized retained-production-copy rehearsal through 0043 with temporary-only rollback/deletion, prove production Stripe/webhook configuration, and assemble signed external acceptance. Production remains HOLD.

2026-07-25 — M8 consent truth normally merged and protected-staging live

  • PR #303 passed hosted CI and normally merged exact source head b30b327fbafd7f874ac84ec1b409dd407378a0fb over base 37495a2de617445667d82774a505c38c0de947d8 as two-parent main 1c142547dec54923d7c154b610fa3e0152011bed.
  • The protected migration controller found only 0043_consent_truth.sql pending, recorded a Time Travel bookmark, applied it, and read back no pending migration. Users 35, wallet transactions 64, market purchases 27, portfolios 36, and leads 99 were identical before/after. Migration receipt SHA-256 is 266bb4fd6bff17b1da71f8a52caac7fb2f0bbbf556e018e331ebf685fb7276f8.
  • The protected deploy controller uploaded exact source tree 4818722d74931f524cdf0ee644847389bf1653db and assets 57efda7c213b796133387369494f1ee0f2376a8c17ec373860b90ebbef35321d as Worker 6fba2fcd-3b21-4fc8-b654-3795bd3f2867 / deployment ca805c8b-7fc6-4555-83d3-da261599a0f7. Live base/Stripe health agree on full SHA and sandbox acct_1TtjDjPuLV917S5K.
  • Authenticated Market, My Leads, Activity, Territories, Billing, and Settings passed 1440x900 and 390x844 with no horizontal overflow, clipped visible controls, console errors, or >=400 application requests. Hosted Admin rendered the M8 missing-evidence and manual-attestation states at 390x844; the temporary demo-admin flag returned to 0 and its total/purchased 708000 cents plus held/promotional 0 remained unchanged.
  • Fair Home Cash built 966 pages and uploaded 1,195 assets as code version 44fc9887-771c-4594-abfc-71de90f78137. Although Wrangler's route-update call returned Cloudflare 10000, provider readback proved deployment 4191ff34-c639-4621-b6f9-e79f73b21da7, the enabled apex domain, and the exact five-minute schedule.
  • Because live FHC forwards to production Soldi while production Soldi remains pre-M8, only FHC_INGEST_SECRET was removed. Secret-change version b4252ade-8dbe-4ec6-bb44-d201ac02ea29 / deployment 024200b9-9b48-40e9-9c11-cd73607c3cd8 preserves KV, Resend, domain, schedule, and the new verifier. Valid leads remain persisted/alerted and forwards remain pending without retry exhaustion. Non-writing live probes returned 400 missing_consent_evidence and 400 invalid_consent_disclosure.

Next up: rebind exact-candidate Stripe acceptance, run the retained-production-copy rehearsal through 0043 with temporary-only rollback/deletion, obtain physical-iPhone and signed external acceptance, then promote production. Restore the FHC bridge secret only after production Soldi runs M8 and prove one-time queue reconciliation.

2026-07-25 — M8 consent-truth candidate (local source and browser proof)

  • Exact base/main is 37495a2de617445667d82774a505c38c0de947d8; the source candidate is codex/consent-truth-20260725. Protected staging remains exact M7 application 53172e598a5539be7d36f3cd9d0178370109dda1 through applied 0042; migration 0043_consent_truth.sql has not yet been applied or hosted.
  • 0043 adds explicit verified / attested / missing evidence state, disclosure version/hash, and the latest-overall consent index. Historical thin rows stay nonmarketable; only explicit admin_manual_attestation history becomes attested.
  • FHC now verifies a real checked, exact allowlisted English/Spanish disclosure before storage, captures disclosure hash plus IP/user agent or approved provider tokens, rejects forged/missing evidence, and keeps a durable retry/reconciliation pointer without exhausting it while the bridge secret is unconfigured.
  • Admin manual intake records an honest operator attestation and stays unavailable for sale. CSV “verified” rows require TrustedForm or Jornaya evidence. Approval, Market, bulk, Territory, Package, bid, auction buy-now, and scheduled auction settlement all require the latest consent row to be complete and verified.
  • Purchased-lead responses expose a compact owner-only intake record with status, source, method, captured time, disclosure version, and a lawful-basis reminder. They do not expose pre-purchase provenance or claim TCPA authorization.
  • Root verification passed 101 files / 923 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. FHC passed 566 tests, built 966 pages, and audited with 0 blockers and 12 pre-existing thin-content warnings.
  • Exact local browser QA passed the new Admin and dossier states at 1440x900, 390x844, and 320x844: zero document overflow, clipped active-dialog controls, console errors, or failed application reads. The 320px Admin attestation card remained fully usable.

Next up: open the ready normal-merge PR with Zak as reviewer, merge after CI/QA, apply sole pending 0043 through the protected-staging controller, and rerun authenticated hosted proof. Production remains HOLD for final-candidate retained-production rehearsal/rollback, live Stripe, physical-iPhone, and signed external acceptance.

2026-07-25 — M7 protected-staging deployment and authenticated readback

  • PR #301 normally merged source head dd44cd576d9edd8b31019e55ed202595213b2dbe over base 7678d449b97bfd4f440f79363d04907e2e8a4da7 as exact two-parent application authority 53172e598a5539be7d36f3cd9d0178370109dda1. This is the deployed application authority; a later docs-only receipt descendant is not.
  • Protected staging applied its sole pending migration, 0042_admin_financial_resolution.sql; post-apply pending migrations are empty. The pre-apply Time Travel bookmark receipt hash is 616cbef0756295a50dea4597646270f6b64ed8fd11bb36572ead6cdc11a0c8e1. The exact source-tree, assets, and migration digests are 52aecf63915f09ee08ac2cb576d324c57f068938, e08c0dc436284e5c351c5a56b2184e9820c0a07b84135b4c56fba6fdd33102ab, and a3f4d17c6f9610b0deb29a54e0c89fe5c29e80399196b37009e30dae1df6779c.
  • Cloudflare readback identifies Worker 93bf0d59-a716-4460-a521-5add5e8e94d7, deployment 4e74a35f-6d5d-4944-b8f0-9c46fbb8f016, and version tag v60-53172e598a55-92a496717b2e-f0945ce6dc1b42b785b6d4805b1045a1. Live health and Stripe health bind the runtime to test account acct_1TtjDjPuLV917S5K.
  • Authenticated Admin exact buyer lookup passed and returned immutable ledger/reversal arrays; it made no credit or resolution mutation. The temporary staging demo-admin flag was restored to 0; balances remained total/purchased 708000 cents and held/promotional 0.
  • Admin visual QA at 1440x900, 390x844, and 320x844 had no overflow, rendered buyer evidence, retained 44px mobile controls, sent 24 requests all 2xx/302, and logged no console errors. The six buyer routes at those same viewports had no overflow, signed-out/fatal state, console errors, or >=400 response among 49 preserved requests. Local /tmp screenshots are operator-local evidence, not durable repository artifacts.

Next up: close the remaining consent/provider/UI and owner-decision blockers, bind the resulting exact merge as the final candidate, and only then run the final production-data rehearsal/rollback plus physical-iPhone/external acceptance. Broad production promotion remains HOLD.

2026-07-24 — M7 admin financial resolution source candidate (local only)

  • Exact current main/base is 7678d44; the source candidate is on codex/admin-financial-resolution-20260724 and has not merged, applied migration 0042, or changed protected staging. Historical protected staging remains exact application 003c744 through migration 0041; no hosted, staging, or production deployment claim is made by this entry.
  • Forward migration 0042_admin_financial_resolution.sql adds the operator-financial action, immutable completion/audit, terminal reversal-resolution, and later-provider-event quarantine records. The admin surface requires an exact buyer email or ID lookup; it does not enumerate or fuzzy-search buyers.
  • A correcting credit is positive-only, explicitly split, idempotent, and indivisible from its immutable wallet ledger and audit artifacts. Terminal reversal resolution is permitted only for an active case whose stored Stripe event ID and terminal status exactly match the selected provider evidence; request-key reuse replays the original result and conflicting reuse fails closed.
  • Only a won dispute releases the case's held funds. Lost disputes and closed refunds release zero; any unresolved exposure keeps the account paused. Later provider events for a resolved case are quarantined rather than reopening or mutating the immutable resolution.
  • A first-arriving terminal dispute event never creates a synthetic hold: won records zero outstanding exposure without pausing, while lost records the full outstanding exposure and pauses without a hold. This closes the provider-ordering case before operator resolution.
  • Local QA passed the complete 101 app files / 914 tests, production controls 21 / 21 with 123 assertions, and exact Chrome/Playwright checks at 1440x900, 390x844, and 320x844 with no document overflow, console errors, or failed requests; the exact buyer lookup path was exercised. This is local source/test/browser evidence only, not a hosted receipt.

Next up: independently review and normally merge this source candidate before any migration-first protected-staging run. Broad production promotion remains HOLD.

2026-07-24 — Refund gaming and genuine signed dispute replay pass

  • On exact protected-staging application 003c744, client-supplied refund counters/timestamps and contact createdAt returned 400; non-owner evidence returned 404; one idempotency replay returned the same attempt; and six real server-written Call/Text attempts compressed into about 1.4 seconds still returned 409 refund_touchpoint_gate_not_met with zero elapsed days. D1 retained exactly six eligible/distinct attempts and zero refund request/claim.
  • A fresh staging Investor with the normal $500 promotional signup credit completed one genuine $1,000 Stripe-hosted sandbox Checkout using the provider's fraudulent-dispute test card. Checkout cs_test_a1m84ta3ll9mTiCklgiUF1W2Rw7Dy0Nt7HtE9fN7Ys8qQMTr03DtANCLVK funded PaymentIntent pi_3Twwr6PuLV917S5K2FpphlwW exactly once.
  • Dispute event evt_1Twwr9PuLV917S5Kmy1dCL5P initially received retryable 503 while funding authority converged, then Stripe automatically retried to 200. It created one active fraudulent dispute, paused the buyer, held exactly $1,000 purchased exposure, left the unrelated $500 promotional balance available, and recorded no outstanding exposure.
  • Four manual signed Stripe Workbench resends returned 200. Final D1 state remained one funding claim/evidence/deposit, one reversal case/event/hold, balance=150000, held=100000, purchased $1,000, promotional $500, and account_paused=1.
  • The browser session was signed out and no cookie/password/secret/raw-payload artifact was persisted. Public copy delta: none. Durable receipt: artifacts/soldi-completion-2026-07/shots/refund-dispute-redteam-hosted-receipt-20260724.md.
  • Final repository proof passed 98 app files / 893 tests, TypeScript, Vite, transparent-brand audit, production controls 21 / 21 with 123 assertions, docs build 10 internal + 2 client docs + index, readiness JSON validation, and diff hygiene.

Next up: publish the docs-only receipt, then close production Stripe/admin/consent configuration and final-candidate rehearsal/device gates. Broad production promotion remains HOLD.

2026-07-24 — Production demo access revoked on the deployed legacy runtime

  • A fail-closed production probe found that the static-brand production runtime still exposed demo@soldi.cc / soldidemo, /api/v1/auth/demo, and already-issued U_SEED_GHOST sessions. Production health had no source SHA, so provider history was reconciled to static-social source 55efa35922e9df2be159e0de28587f8e90ef386b.
  • A production-only emergency snapshot was cut from that exact live source. Commit f429daac23dafb782ba36ce9a9d03faa5e4cfbc0 blocks current and legacy demo emails before login D1 access, removes canonical/query-flag demo login, and rejects both seeded demo user IDs through ordinary and admin session guards before D1.
  • Focused proof passed 42 tests / 117 assertions. The complete historical runtime passed 34 files / 270 tests, TypeScript, Vite production build, Wrangler dry-run, and diff hygiene. Independent Terra/high review found no remaining direct session-verification bypass.
  • Cloudflare uploaded no changed asset files and activated the Worker-only fence as version 12a6b797-7d38-4aaf-85c0-bb1b2aaa0ce8 / deployment 181a0528-37a4-43a1-bf59-f007a3f298f2. No migration, secret, Stripe configuration, D1 correction, UI bundle, or public copy changed.
  • Hosted proof returned 401 invalid_credentials with no cookie for the demo login, 404 not_found/no-store with no cookie for /auth/demo, {"user":null} for a session issued before the fix, and 401 unauthorized for both a buy mutation and admin read using that session. Health remained 200.
  • The pre-fix cookie artifact was deleted and verified absent. Historical demo wallet/ledger rows remain inert production audit history pending a separately authorized data-correction decision.

Next up: publish the docs-only receipt, then execute refund-attempt gaming and a genuine signed charge.dispute.created freeze/replay. Broad production promotion remains HOLD.

2026-07-24 — Exact-staging two-buyer race and PII preview pass

  • Created one unmistakably synthetic $150 open-market lead and two fresh staging-only Investor accounts on exact staged application 003c744. Each account started with the normal server-recorded $500 promotional balance; no production or provider payment was touched.
  • Before purchase, both Market payloads contained the lead's price/status but none of its seeded seller address, name, phone, or email keys or values.
  • Simultaneous authenticated buys returned one 201 purchased and one 409 lead_unavailable. D1 contains exactly one sold lead, purchase, portfolio, immutable $150 debit, completed fulfillment claim/completion, and batch guard. The winner has $350, one win, and one spend; the loser remains $500, zero wins, and zero spend.
  • Winner replay returned 200 already_owned; loser replay remained 409; purchase/portfolio/debit/claim/completion counts stayed exactly one.
  • All staging cookie jars and transient response/status artifacts were deleted and verified absent. Synthetic economic rows remain only in isolated staging as auditable red-team evidence.
  • Public copy delta: none. This closes Zak's two-buyer/same-lead and pre-purchase PII cases for exact staged 003c744; production-demo isolation, refund gaming, signed dispute creation, device, and production gates remain open.

Next up: publish the docs-only receipt, then execute production-demo isolation and the remaining provider/refund cases. Production remains HOLD.

2026-07-24 — FHC five-minute alert control live and provider-proved

  • Ready PR #296 requested killerabbasi, passed hosted FHC CI, and normally merged exact head 41c95804471189aa5fd928027a789e96c9af2697 over e60cc994d0e0e78e8bb9556587565e92615b3b49 as two-parent main 6a20c11ac285c2fbbd184882997b6a0a5106825e.
  • A clean exact-main deploy uploaded the 966-page FHC build and activated Worker version e714d690-3bdc-4d2d-bc23-95b323848d60 at 100% through deployment e06561d3-effc-46b3-9241-f199fad60674. Wrangler's final zone-route call returned Cloudflare 10000, but provider deployment readback and the live domain's new authenticated-endpoint 401 prove the existing custom domain advanced.
  • The upload did not apply the new cron. The Workers Scripts schedules API accepted */5 * * * * and an immediate readback returned that exact trigger.
  • One synthetic Cameron-only KV lead/pointer produced a pre-SLA sent receipt at 03:20:22Z, owner camolechowski@gmail.com, retry count 0, and provider message cffb7af8-d167-47ce-8b3e-8362ba86f56a; Resend reports delivered.
  • Reinserting only the pending pointer caused the next cron to clean it without changing the provider message or retry count, proving the terminal hosted path does not resend. The synthetic lead, pending pointer, and receipt were deleted and verified absent.
  • Public copy delta: none. The subsequent human pending_review owner/SLA remains open, as do Zak's remaining money-path red-team, device, final-candidate, rehearsal/rollback, and production gates.

Next up: publish this docs-only hosted receipt, send Zak the exact live link/version evidence, then continue the remaining adversarial cases. Production remains HOLD.

2026-07-24 — Signed refund replay, hosted password recovery, and FHC alert control

  • Reconciled current source e60cc994d0e0e78e8bb9556587565e92615b3b49 as a docs-only descendant of staged application 003c744fe332594d3f2d6b1619aade3178ab07c8; no Worker upload or migration was needed for these provider/hosted checks.
  • A real $2,500 Stripe sandbox refund generated charge.refunded event evt_3TwumGPuLV917S5K0mGdlCMQ. The staging webhook had only checkout.session.completed enabled, so the provider correctly showed zero deliveries and D1 remained unchanged. The endpoint was narrowed to the three event types the Worker actually handles: Checkout completion, refund, and dispute creation.
  • Two signed Dashboard resends returned 200. The first created one active refund case/event, paused the isolated buyer, kept purchased/promotional/held/total wallet values at zero, and recorded $2,600 outstanding exposure including the full $100 bonus. An authenticated purchase then returned 403 account_paused; the lead stayed available with no purchase or debit. The second resend left exactly one case/event and unchanged wallet/outstanding state.
  • A fresh staging-only account using Cameron's controlled Gmail alias completed the hosted password-recovery loop: register 201, generic request 202, real email from Soldi <account@notify.soldi.cc>, canonical staging fragment link, reset 200, and new-password login 200. The one-time token and temporary response artifacts were deleted immediately.
  • The FHC source candidate now writes a durable PII-free alert:<lead-id> receipt for every contactable lead, binds owner/SLA/attempt/retry/provider state, uses a stable 24-hour Resend idempotency key, and reconciles a bounded expiring pending-alert index from a native Cloudflare five-minute cron. Retries are paced to the five-minute boundary, record an explicit SLA-breach timestamp, and become a durable observable exhausted state after six unsuccessful attempts instead of silently aging out. The authenticated operator route returns aggregate counts only.
  • FHC focused proof is 12 tests / 56 assertions; its complete workspace is 559 tests / 5,259 assertions; the fresh 966-page build and launch audit pass with 0 blockers and the 12 pre-existing thin-page warnings. Wrangler dry-run compiles the scheduled Worker. Root verification remains 98 files / 893 tests, TypeScript, Vite, the transparent-brand audit, and production controls 21 / 21 with 123 assertions. This source control is not live until its ready PR normally merges and exact merged FHC Worker deploys.
  • These are exact staged/provider receipts plus local FHC source proof, not production authorization. Remaining same-lead race, production-demo isolation, refund-gaming, actual dispute creation, PII masking, physical-iPhone, final-candidate rehearsal/rollback, and external acceptance stay open.

Next up: independently review, normally merge, deploy, and hosted-prove the FHC alert control, then continue the remaining red-team cases. Production remains HOLD.

2026-07-24 — Protected-staging money red team and wallet-race hotfix merged

  • The protected migration controller applied 0040_atomic_auction_buy_now.sql then 0041_stripe_reversal_response.sql to D1 soldi-staging under a Time Travel bookmark, verified retained data, and deployed exact clean main c6eb03b558330e04d51d8edb3726aad5d2cdf763 as deployment 44f21e4d-f287-44f6-a8c2-6622206ed605 / Worker 33b77ce9-e6bc-438c-9f62-69c47c8b1680. Health, migration tip, and Stripe test account acct_1TtjDjPuLV917S5K agree.
  • A genuine hosted Stripe Checkout credited $2,500 principal plus the advertised $100 deposit bonus exactly once. Multiple signed Dashboard resends of evt_1TwumIPuLV917S5KSo7xwjpp returned 200; one processed event/economic claim, two immutable funding rows, and all wallet totals remained unchanged.
  • An isolated same-buyer/two-different-Warm-lead race started with exactly one lead's balance. One purchase/debit/ownership committed, the other rolled back, and the wallet remained non-negative; the loser nevertheless returned 500 because the intentional completion-guard failure had no same-lead purchase row for the existing recovery branch.
  • The source fix maps only the exact lead_fulfillment_batch_guards.lead_id non-null conflict to 409 purchase_state_changed; unknown database errors still rethrow. It adds fake-D1 classification coverage, a real-SQLite same-buyer/different-lead regression proving one economic outcome, and an approved-refund regression proving no lead relist/status mutation.
  • Focused proof passes 3 files / 22 tests. Full root verification passes 98 files / 893 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. No buyer-facing UI or public copy changed, so the UI polish and screenshot workflow is not applicable.
  • Ready PR #294 requested killerabbasi, passed hosted changes and bun verify, and normally merged exact head 7bf9ec1523fc0d1c850f4d1b7607772603e5d3ee over c6eb03b as two-parent main 003c744fe332594d3f2d6b1619aade3178ab07c8.
  • The protected controller confirmed no pending migration after 0041, then deployed exact merge 003c744 as deployment 5521e77a-ebf0-4aae-8c81-53bc4fd76f8c / Worker e2d5c349-a806-46e6-b6ce-deab9e87592a. The hosted rerun returned one 201 and one 409, zero remaining wallet, one sold and one available lead, and exactly one purchase/portfolio/immutable debit. Health and Stripe identity bind the exact merge and expected sandbox account.

Next up: complete the remaining money red team, password-reset delivery, FHC queue ownership/alerts, hosted browser matrix, and physical-iPhone proof. Production remains HOLD.

2026-07-24 — Stripe reversal-response and economic pause merged

  • Started from exact docs-only main ed25da4161ce78b239e4bc6c666f42548a5a1ad7 over merged application authority d61d0b80ecc0fa95f6d7e48e1a1eb90b83a12ebc in isolated branch codex/chargeback-m6-20260724. Protected staging remains historical e10a72566b76f5fc004c41d057fdfe751f82fb52; no Cloudflare, D1, Stripe dashboard, staging, or production mutation occurred.
  • Forward migration 0041_stripe_reversal_response.sql adds bounded funding evidence plus append-only dispute/refund case and event state. Checkout funding records name/email/phone/country/postal-code evidence atomically with the existing event/economic claim, wallet credit, and immutable ledger rows; raw Stripe payloads are not stored.
  • After existing signature verification, charge.dispute.created and cumulative charge.refunded bind only through persisted payment_intent_id. Wrong mode/currency/amount is acknowledged without mutation; missing schema or funding authority and stale atomic races remain retryable.
  • A dispute pauses the buyer and holds currently available credited exposure. A refund pauses the buyer and reverses available promotional/purchased cents without making any wallet component negative. Partial events include proportional deposit-bonus exposure; a full refund removes the full principal and full associated bonus. Unavailable remainder persists explicitly as outstanding_cents, and cumulative deltas carry prior outstanding exposure forward.
  • Exact wallet-state and cumulative-provider compare-and-swap predicates plus a final non-null batch guard make stale snapshots roll back. A buyer with an active reversal case cannot self-unpause; an explicit operator-resolved state preserves a future safe resume seam. Package activation, candidate/final delivery, renewal, bid placement, and scheduled auction selection/debit/portfolio writes all fail closed across pause races.
  • The controller authority is now 41 migrations total: production's retained baseline remains 24 applied (00010024), and the next rehearsal expects 17 pending (00250041). Deployment order is 0040, then 0041, then the exact merged Worker.
  • Final focused proof passes 6 files / 93 tests plus TypeScript and diff hygiene. Full root proof passes 98 files / 891 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. This backend-only slice changes no buyer-facing copy or UI, so the UI polish/screenshot workflow is not applicable.
  • Ready PR #292 contained immutable application commit 09b48cc34097f1aa8c13851199302f2562cbfcba plus receipt-only descendants, with killerabbasi requested and public copy delta none. Exact final head d5477c8243e97e8f384d989318cf43c4fdecca0a passed hosted changes and bun verify, then normally merged as exact two-parent main ca97b1342d3712d49db47fd0468936cdcb74749f (ed25da4 + d5477c8). Migration-first protected staging and every provider/device receipt remain open.

Next up: mint a fresh migration-first protected-staging receipt for exact merged main ca97b13, applying 0040 then 0041 before the Worker, and run signed sandbox dispute/refund plus authenticated browser and physical-iPhone acceptance. Terminal dispute resolution and admin treatment of outstanding exposure remain explicit follow-ups; production stays HOLD.

2026-07-24 — Server-authoritative refund window merged

  • PR #289 normally merged M4 as exact main d0bb9e4dd235a5b73b51d6e10233de4176b8ef2e; protected staging remains historical e10a72566b76f5fc004c41d057fdfe751f82fb52 and no provider, D1, Stripe, staging, or production mutation occurred.
  • M5 preserves the reason-independent minimum of six owner-scoped, server-written Call/Text attempts spanning 72 hours. The strict request body still rejects client counts, timestamps, and upload/proof fields; email, pre-purchase, malformed, and future attempt evidence cannot authorize a refund.
  • The refund route now derives an inclusive rolling seven-day window from the owned portfolio's persisted purchased_at plus the Worker clock. Missing, malformed, future, and older-than-seven-day purchase timestamps fail closed before source-debit resolution or any refund write.
  • The only buyer-copy delta is the rejected-request message The 7-day refund window for this lead has closed. No proof-upload UI, table, bucket, binding, or retention obligation was added.
  • Focused proof passes 3 files / 25 tests plus TypeScript. Full root proof passes 96 files / 874 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. The required polish workflow still cannot parse its pre-existing top-level ECMAScript-module return; manual make-it-sexy review plus three native make-it-simpler lanes found no unresolved P0–P2 in the exact changed source.
  • PR #290 requested killerabbasi, passed hosted changes plus bun verify, and normally merged as exact two-parent main d61d0b80ecc0fa95f6d7e48e1a1eb90b83a12ebc (d0bb9e4 + reviewed head 367e838). Protected staging and every provider remain untouched.

Next up: continue M6 dispute/chargeback response as the next source blocker. Migration 0040 still must precede the next protected-staging Worker deployment; M3 provider receipt, M4 retained production demo history, and all hosted/promotion gates remain separate.

2026-07-24 — Production demo isolation candidate

  • Started from exact normal main merge 289b877bf9a45d5a63b4c4c92694c691c921ba87 in isolated branch codex/production-demo-isolation-20260723; the root checkout and protected staging were not mutated. Protected staging remains exact e10a72566b76f5fc004c41d057fdfe751f82fb52.
  • One fail-closed environment authority now permits fixture data only in explicit development, test, or staging. Production /auth/demo returns 404 before D1, ?demo=1 cannot mint a session, current and legacy demo credentials return generic 401, and already-signed sessions for either demo identity resolve to no user.
  • Market list/direct-buy/bulk-buy exclude all six canonical v60 IDs, legacy L_MKT_* IDs, and seed:// source/landing provenance outside trusted fixture environments. Scheduled restock no-ops there even if auctions are later enabled.
  • Non-interactive economic paths reject both U_DEMO_V60 and U_SEED_GHOST: Stripe webhooks acknowledge them as ignored without a claim/credit, auction settlement cannot select their bids, Territory allocation skips their orders, Package renewal/routing skips their subscriptions and orders, and production Package-readiness excludes their Package/Territory demand plus fixture/seed supply.
  • Existing fixture-dependent SQLite tests now opt into APP_ENVIRONMENT=test explicitly. Focused route/SQLite coverage includes auth/session, Market single/bulk purchase, Stripe, settlement, Territory, Package renewal/routing/readiness, and scheduler behavior, with explicit staging preservation checks. Full app proof passes 96 files / 868 tests plus TypeScript.
  • This backend-only candidate changes no buyer UI or public copy, so no application screenshot recapture or post-change UI polish is applicable. A fresh direct Zak-message lookback found no newer product request after his July 23 master packet and exact-SHA re-audit.
  • The source patch makes the historical production demo balance economically unreachable but does not rewrite retained D1 history. A separate production-only, before/after-receipted correction is still required before claiming the stored balance itself is zero.

Next up: complete root/docs/control verification and independent review, publish one ready PR with killerabbasi requested, and merge normally after CI. Then proceed to M5 server-authoritative refund eligibility. Migration 0040 still must precede the next protected-staging Worker deployment.

2026-07-23 — Buy-now atomicity and truthful Stripe bonus ledger candidate

  • Started from exact normal merge/staged baseline e10a72566b76f5fc004c41d057fdfe751f82fb52 in isolated branch codex/money-blockers-atomicity-20260723. Zak's source audit identified a real auction buy-now race: the route pre-read state and then unconditionally batched bid, debit, sold state, and ownership writes.
  • Forward migration 0040_atomic_auction_buy_now.sql adds one immutable claim per auction/lead plus a final commit guard. Every bid, promotional-first debit, sold-auction mutation, portfolio, own-hold conversion, and exact displaced-leader release is conditional on that claim; the guard aborts the entire D1 batch unless all economic artifacts agree. Same-winner retries return the original portfolio without charging again, while another buyer receives 409.
  • Stripe funding already had same-batch event/economic claims, signed-event validation, and exactly-once replay recovery on e10a725; those invariants were preserved. The advertised promotional amount now writes a distinct immutable deposit_bonus credit beside the principal Stripe deposit in the same batch. Invoice funded totals include both rows and same-timestamp Activity ordering is deterministic.
  • Fresh real-SQLite proof starts two buyers from the same pre-claim state and gets exactly one 201, one 409, one debit/portfolio/claim/guard, correct aggregate balance, and no negative wallet. Additional cases prove own-held affordability, exact displaced-leader release identity, same-winner idempotent retry, and total rollback after an injected portfolio-write failure. Focused money/read-model proof passes 6 files / 44 tests plus TypeScript.
  • Three independent native reviews found and closed winner retry, budget/pause compare-and-swap, exact release-row binding, invoice funding aggregation, and ledger-order issues. Migration review found no backfill rewrite or D1 SQL blocker. Operational order is strict: apply 0040 before deploying the Worker; code-first rollout intentionally fails buy-now closed with 503 auction_buy_now_schema_not_ready.
  • This candidate changes no buyer-facing copy or UI and therefore needs no screenshot/deck recapture or post-change UI polish. No Cloudflare, D1, Stripe provider, staging, or production mutation occurred.

Final proof passes 95 files / 849 tests, TypeScript, Vite production build, transparent-brand audit, production controls 21 / 21 with 123 assertions, docs build (10 internal + 2 client docs + index), release-readiness JSON parse, and diff hygiene. The production rehearsal controller now pins 40 total migrations and the exact 16-migration 00250040 pending set.

Next up: publish one ready PR with killerabbasi requested and merge normally after CI. The future protected-staging rollout must migrate before Worker upload and mint fresh exact-merge concurrency/Stripe/hosted receipts; production remains separate. Then continue Zak's ordered M4/M5 money blockers.

2026-07-23 — Hosted 320px Market/Territory target hotfix

  • PR #286 merged normally as 73153a87ed7f046b91f828e1e07d177332c581cd; protected staging deployed that exact merge as deployment 8df8e4b4-d200-487f-8346-4d1dde0d0334, Worker version b1d8488d-259f-4181-a65e-46670d0ccc6b. Health and Stripe-health readback matched the full SHA/version and the expected Stripe sandbox account.
  • Authenticated hosted QA found three bounded CSS defects at 320px despite clean document width: the Package recommendation actions were 42px, Territory bid steppers could flex below 44px, and the desktop Remove cell leaked through a more-specific !important table rule. A same-row bid/cap arrangement was also too crowded at the narrowest viewport.
  • The isolated hotfix restores 44px recommendation and bid targets, hides Remove with a specificity-safe selector, changes the 120px card ceiling to a content-safe minimum, and stacks bid/cap controls only at max-width:340px. The 390px card retains the compact two-row hierarchy.
  • Fresh local authenticated automation passed 22 route/viewport rows with no application failures. Rendered 320px inspection shows separated bid and weekly-cap rows, no clipping or overlap, and 44px controls. Three native Terra/high reviews were clean on reuse and efficiency; the quality review's 320px geometry concern directly produced the stacked narrow-screen revision.
  • Final proof passed 93 files / 842 tests, TypeScript, Vite production build, brand audit, production controls 21 / 21 with 123 assertions, docs build (10 internal + 2 client docs + index), release JSON parse, and diff hygiene. The required polish workflow remains blocked before execution by its existing top-level-return parser defect; manual/native review and rendered inspection completed instead.

Next up: publish and merge the ready hotfix PR with killerabbasi requested, deploy its exact normal-merge SHA through protected staging, repeat hosted 320/390 QA, and send Zak that exact link/SHA for the physical-iPhone pass.

2026-07-23 — Zak final mobile, Package, refund-gate, and legal candidate

  • PR #286's local candidate preserves exact staged baseline ea9c091a43bae4ce5706d6ef5b07b79e5b87d327 while closing Zak's latest phone and money-trust findings. The shared mobile navigation, dense Market/My Leads/Territories/Activity/Wallet hierarchy, owned-share privacy default, session resiliency, fund-and-return flow, and buyer-facing ledger copy remain intact.
  • Refunds now use the locked original touchpoint design for all nine reasons: no uploads or proof storage, at least six server-tracked Call/Text attempts across three days on the purchased portfolio, the exact work-first copy before unlock, a required reason, optional details, and no economic/refund write on a gate failure. Transaction eligibility and pending state are portfolio-scoped and use set-based summaries instead of per-row correlated scans.
  • Wallet visibly discloses the full Package commitment as $5,000/mo and 25 Hot leads at $200 each on phone. Terms, Privacy, and Acceptable Practices remove draft/placeholders/Wyoming residue and consistently use Illinois formation, Cook County, support@soldi.cc, the Soldi/Fair Home Cash mailing address, July 22, 2026 dates, and the drafted $50,000 cap.
  • Focused proof passes 8 files / 53 tests. The complete pre-documentation gate passes 93 files / 842 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21/21. Local browser proof covers 22 authenticated route/viewport rows at 320×844, 390×844, and 1440×900 plus the phone refund sheet and all three legal pages with no overflow, console/page/application-network failures, native selects, undersized controls, or sub-16px inputs. Receipts are under /tmp/soldi-zak-final-browser-proof-v2/.
  • The required repository polish workflow was attempted but cannot parse under Bun because .claude/workflows/post-change-polish.js contains a top-level ECMAScript-module return; native Make it Sexy / Make it Simpler reviews and rendered visual inspection were completed instead, and the tooling failure is recorded rather than mislabeled green. Zak confirmed the item-40/package/legal direction and instructed the team to finish exact SHA plus staging receipts before triaging his separate safeguard red-team packet.

Next up: final exact-tree verify, ready PR receipt/reviewer/CI, normal merge, protected-staging deploy and hosted 320/390/1440 proof, then send Zak the exact SHA/link for his physical-iPhone pass. Production remains separate.

2026-07-22 — Exact mobile candidate staged; 320px Wallet label follow-up

  • PR #284 merged normally as 9203b5c2f677f62542a8c87146aac02775b2d572 (parents b0974b2 / a40c16c). No migrations were pending through 0039; protected staging deployment 71936e79-fb82-4243-9578-174255e057cf / Worker version e0935b95-7069-4f07-832a-0103ef29f227 serves that exact merge with test Stripe account acct_1TtjDjPuLV917S5K.
  • Its receipt-bound non-mutating Territory plan proved exactly three marker rows, zero order references, and zero Orange/Will/Dallas competitors. The guarded apply produced exact Orange/Will/Dallas shapes at positions 1,1,1; wallet/purchase/refund/outcome/portfolio counts stayed 24/6/5/1/15, and all prior lead/economic history remained.
  • Authenticated hosted Market/My Leads/Territories/Activity/Wallet/Settings sweeps at 320, 390, and 1440 pixels had exact document width, no horizontal overflow, no console errors, and no failed app requests. The stricter 320px Wallet capture found only Pay per lead ellipsizing; a one-rule candidate reallocates existing grid space and proves all three choice labels unclipped. The complete gate passes 85 files / 791 tests, TypeScript, Vite, brand audit, production controls 21/21 (123 assertions), docs build, and diff hygiene; three independent reviews are clean.

Next up: full gate, ready follow-up PR, exact merge/redeploy, hosted label/share readback, then Zak's physical-iPhone pass.

2026-07-22 — Territory target-context collision correction

  • PR #283 merged normally as b0974b2cae192e2f2f2fbe4a30cd228e5440acfd; protected staging deployed that exact merge after a no-op migration receipt. The first receipt-bound territory-plan made no write and refused because another buyer already owns an active Broward FL Territory, proving the target-context guard works against live drift.
  • The correction replaces only the proposed Broward target with Orange County FL; Will IL and Dallas TX remain. Existing Essex and Broward orders stay untouched. Exact-shape readback and wrong-but-distinct rejection continue to bind every marker ID's name and filters.
  • Verification is green: focused controller 21/21 tests (117 assertions), full app 85 files / 791 tests, TypeScript, Vite, brand audit, production controls 21/21 (123 assertions), docs build, and diff hygiene. Independent exact-candidate review returned READY with no P0-P2 finding.

Next up: repeat the focused/full gates and exact review, normally merge, mint a new exact-merge receipt, rerun the non-mutating plan, then apply only if it proves collision-free.

2026-07-22 — History-safe staging Territory refresh follow-up

  • PR #282 merged normally as exact main 4da97bd45e3491fe3073610541289a4bb186b4ca after hosted CI and exact-candidate review. Protected staging migration readback was a no-op through 0039; deployment a570bdfa-e50d-4cc0-8fc2-a35139359dcb / Worker version b7038a04-d136-40d0-b95f-258b9e1e1559 now serves that exact merge.
  • The guarded v1→v2 demo-seed dry-run refused with demo_seed_fixture_has_economic_history, correctly preserving one purchased/portfolio-backed legacy fixture lead. Read-only D1 proof found three marker-owned legacy Territory orders with zero lead_allocation_claims and zero portfolios references, plus one unrelated retained Essex order.
  • This follow-up adds a separate receipt-bound territory-plan / territory-apply path. It updates only the exact three marker-owned, unreferenced legacy Territory rows in one guarded D1 batch; leads and all economic tables remain untouched. Broward FL, Will IL, and Dallas TX avoid the retained Essex context and must read back as the exact per-ID names/filters in three position-1 partitions. Focused proof passes 21/21 tests (117 assertions), including economic-history preservation, wrong-but-distinct target rejection, and before/after ledger equality. The complete gate passes 85 files / 791 app tests, TypeScript, Vite build, brand audit, and 21/21 production controls (123 assertions); docs rebuilt and exact-candidate review returned READY with no remaining P0–P2. No follow-up D1 mutation has run yet.

Next up: exact-head review, ready PR/CI/normal merge, fresh exact-merge staging receipt, Territory plan/apply, and hosted 320/390/1440 QA before Zak receives the link.

2026-07-22 — Zak iPhone final-polish + owned-share candidate (local; not deployed)

  • Re-read Zak's direct-message rows 280385280388 and verified no newer direct Soldi instruction supersedes them. The phone bottom rail now owns Market, My Leads, Territories, Activity, and Wallet; the avatar menu contains only Refunds, Settings, and Sign out; and /transactions presents the single visible label Activity without changing its route or ledger API.
  • Settings now defaults to one compact Account card with an on-demand profile editor, truthful non-control security copy, tight Notifications/Lead delivery status rows, and Retake setup. It removes the duplicate Payment & Budget shortcut, duplicate default name/email fields, disabled two-step toggle, and disabled delivery-radio affordances. Wallet removes only the Monthly budget UI while retaining all backend cap fields/APIs/enforcement; it shows balance in exactly the top bar and wallet hero, preserves a 44px Add funds control, and fixes the clipped Three ways to buy heading. Market uses the tighter subtitle and compact dismissible Package recommendation without changing readiness or pricing.
  • My Leads adds owned-lead Share actions to list and board cards. The launch flow loads the owner-scoped lead detail, then shares exact address, property line, estimated value, and Google Maps URL through Web Share with clipboard fallback. Include seller contact is off on every open; phone/email/name are absent until explicitly enabled. Load failure closes the sheet with a truthful error. Masked/referral sharing, Apple Pay, and post-call prompting remain in Zak's explicit post-launch sequence.
  • The receipt-bound staging demo seed advances from marker v1 to v2 and will replace only the exact marker-owned, history-free fixture with three distinct county-only rows (Essex NJ, Will IL, Dallas TX). The controller treats both upgrade and legacy cleanup as real transactional mutations, locks three distinct counties at positions 1,1,1, and preserves wallet/purchase/refund/portfolio counts. No remote D1 mutation has run yet.
  • Focused source proof passes, the corrected seed controller passes 19/19 tests (99 assertions), and the final root gate passes 85 files / 791 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21/21 (123 assertions). Exact-candidate review also closed truthful legacy-cleanup receipts and a board-card keyboard bubbling edge case before returning READY. A temporary QA-only .dev.vars symlink was removed after the path-fence correctly rejected it; the clean rerun passed. Docs rebuilt 10 internal + 2 client docs + index and diff hygiene passed. Local authenticated Chrome at 390×844 proves no document overflow, no sub-44px visible links/buttons on Settings/Wallet, no fake Settings toggles/radios, no Monthly budget copy, exactly two visible balance values, an unclipped Three ways heading, matching Activity tab/page title, the three-link avatar menu, and owned-share privacy default/reset. Browser-captured share payloads prove seller contact absent by default and present only after opt-in. Fresh local screenshots are in docs/shots/*final-polish-local-20260722.png.

Next up: rerun the complete root gate after the final Settings compaction/docs update, publish one ready PR with killerabbasi requested, normally merge after exact-head/CI QA, then deploy and v1→v2 reseed protected staging through fresh exact-merge receipts. Hosted 320/390/1440 QA and Zak's physical-iPhone auth/password-reset/share pass remain separate; production is not implied.

2026-07-22 — PR #270 real-app port staged; footer touch-target correction

  • PR #280 passed hosted CI and independent exact-head review against Zak's PR #270 source, then merged normally as eb9ef536fba7c87fb09e266d574f7277fcc83876 with parents 04cb71b71bd1af506608046bc80f3fa5914b0b2d and reviewed head 8fee43b2cca8805441edd98f76611292f970076a. A fresh protected-staging migration receipt bound to that merge found no pending migrations through 0039 and made no D1 mutation. Provider deployment e4f12efc-d5a1-4f57-84be-67e9634d4b22 / Worker version 68d882d6-1839-463e-a0da-2c29d8383928 serves the exact merge at staging.soldi.cc; health and Stripe readback prove the expected SHA and test account acct_1TtjDjPuLV917S5K.
  • Hosted 320×844, 390×844, and 1440×900 automation found no page overflow, console errors, font failures, or broken images on My Leads, Territories, Transactions, or desktop Billing. It also found one bounded shared-shell defect: the five mobile footer legal/support anchors were visually readable but below the locked 44px target. This follow-up makes the mobile footer nav full-width and gives every link a centered 44×44 minimum target; it changes no copy, route, API, D1, Stripe, wallet, Package, or desktop behavior.
  • The focused Layout regression passes 2/2 tests. The repository polish runner was attempted and still fails before execution on its existing Bun 1.3.0 top-level-return error; explicit make-it-sexy review and independent reuse, quality/accessibility, and efficiency reviews all returned clean.

Next up: run the full root gate, land this bounded follow-up through a ready PR, mint a fresh receipt for its normal merge, redeploy protected staging, and repeat hosted acceptance before sending Zak the link for his physical-iPhone pass. Production remains separate.

2026-07-22 — Zak PR #270 exact mobile-mock port (local candidate; not deployed)

  • Reconciled GitHub PR #270 at exact head a29e9c74d27e8d62a5a8f3e6697d6e9a5e16a8f2 and used its sole file, previews/soldi-mobile-preview.html, as the phone visual authority. The real app now carries the mock's compact balance/add/avatar top bar, translucent five-tab rail, searchable separated My Leads cards, labeled Territory cards, two-column transaction ledger, centered wallet balance, compact funding controls, collapsed phone budget editor, and three-way-buy rows. The preview itself remains a mock and is not routed or shipped as product code.
  • Real behavior wins where the static mock is illustrative: lead search/stage/call/export, Territory bid/cap/remove/search, refund actions, Stripe Checkout/card management, budget editing, Package status/payment recovery, invoices, and desktop layouts remain usable. Runtime balances, rows, prices, position, readiness, and recovery state come from the existing APIs; no example value was copied into product state. The only visible copy additions are Balance, Available balance, Call, and Edit budget; no pricing, Package, Stripe, wallet, D1, or worker contract changed.
  • Focused proof passed 7 files / 55 tests plus TypeScript and diff hygiene. The full root gate then passed 85 files / 785 tests, TypeScript, production Vite build, transparent-brand audit, and production controls 21/21 (123 assertions); docs rebuilt 10 internal + 2 client docs + index. Authenticated local-Worker browser proof at exact 320x844, 390x844, and 1440x900 found scrollWidth === innerWidth on My Leads, Territories, Transactions, and Billing. The one 320px My Leads filter item outside the viewport is contained inside the intentional horizontal chip rail; the document itself does not overflow. Fresh 390px captures are in docs/shots/*pr270-port-local-20260722.png. The repository workflow-only polish runner was attempted and stopped on its existing Bun 1.3.0 top-level-return syntax error; explicit make-it-sexy review plus independent reuse, quality, and efficiency reviews found and closed desktop budget access, mobile Package recovery, search preservation, accessible call names, duplicate ledger dividers, and brittle selector issues.

Next up: finish full verification and exact-head review, open one ready PR with killerabbasi requested, merge after QA, mint a fresh exact-merge staging migration receipt, deploy protected staging, rerun hosted 320/390/desktop acceptance, and send Zak the staging link for his physical-iPhone pass. Production remains a separate evidence-bound decision.

2026-07-22 — Zak photo-reference mobile hierarchy pass (local candidate; not deployed)

  • Started from exact main 75ed453d27b00e0f9fd7c87fb8de228e3db29714 in an isolated worktree and treated Zak's four physical-iPhone photos as temporary layout authority while final mocks remain pending. My Leads now restores the phone title/count/export hierarchy and uses named card fields; Territories uses an inline Add action and compact county/status/bid/cap/remove card; Transactions reads as a dense two-column ledger; Payment & Budget leads with the real available balance and condenses the existing fund, budget, and three-way-buy controls. The three ways to buy remain expanded by default on phones while Invoices stays collapsible. The shared phone shell is opaque and compact, retains the avatar/account disclosure, five-tab rail, and all existing routes, and no longer lets the floating support launcher cover phone actions.
  • This pass changes no Stripe, wallet, budget, pricing, Package, lead-stage, Territory mutation, D1, or desktop contract. It deliberately does not relabel historical Territory counters as current-week facts. The only buyer-facing copy addition is the mobile label Available balance; My Leads title/count/export were restored, and Add funds visually condenses to + only at 360px and below while retaining its accessible name and route.
  • Focused UI verification passed 7 files / 53 tests; the complete root bun run verify gate exited 0 (TypeScript, full app tests, production Vite build, transparent-brand audit, and production controls), docs rebuilt 10 internal + 2 client docs + index, and diff hygiene passed. Authenticated local-Worker Chrome proof at 320×844, 390×844, and 1440×900 found zero document overflow on My Leads, Territories, Transactions, and Billing; all visible primary phone controls in the checked selector set were at least 44px; console errors were empty; and all application fetches returned 200. Four 390px viewport captures plus a full-page Billing capture are recorded in docs/shots/; the amended Billing readback proves Lead package open, Invoices closed, and Three ways to buy rendered. The repository workflow-only polish runner was attempted and failed before execution on its existing Bun 1.3.0 top-level-return syntax error; three explicit reuse/quality/efficiency reviews plus the manual token, hierarchy, motion, and simplification pass were completed instead. This is local browser/source evidence, not hosted staging or physical-iPhone acceptance.

Next up: obtain independent exact-head review and hosted CI, send Zak the copy delta, then normally merge and deploy the resulting exact main to protected staging for authenticated phone/desktop QA. Final mocks may supersede spacing/tokens without changing these preserved behavior contracts.

2026-07-21 — Territory phone-card spend-cell specificity correction (local follow-up)

  • Browser QA of exact protected-staging merge bc93cbaa0c4da3b5469eaa7ea242aab70ccdbf2f found the phone card's intended hidden desktop-only Spent · 7 days cell still visible as a stranded, unlabeled $0. The generic mobile .terr-tab td { display:block!important } rule has higher specificity than .terr-week-cell { display:none!important }; the follow-up scopes the hide rule as .terr-tab .terr-week-cell and locks that selector in the existing source regression.
  • The correction changes no copy, desktop presentation, pricing, Territory mutation, D1, or Stripe behavior. Focused Territory verification passed 1 file / 12 tests and TypeScript passed. The default-parallel full app run hit seven unrelated resource-contention timeouts at 778/785; every affected file passed immediately with one worker (5 files / 54 tests). Production build, brand audit, production controls 21/21 (123 assertions), docs build (10 internal + 2 client docs + index), and diff hygiene passed.

Next up: independently review and normally merge this two-line specificity correction, redeploy exact main to protected staging, then repeat real-width card/navigation QA before requesting Zak's physical-iPhone retest.

2026-07-21 — Zak physical-iPhone navigation and Territory card follow-up (local; not deployed)

  • Started from exact main 061380b272bd2d85859e7aaf07e6ff85839fed4d in the isolated codex/zak-mobile-feedback-20260721 worktree. The phone avatar menu now exposes My Leads, Transactions, and Refunds before its existing Settings/Sign out controls, but only below 641px; desktop rail and account menu behavior stay unchanged.
  • Phone Territory rows now use a compact named-grid card: county/state with status and server position, labeled 44px bid and weekly-cap controls, and a restrained text Remove action. The prior desktop spend cell remains unchanged, the card never renders a raw territory ID, and search copy is now County or state. Removal now requires a named confirmation before the existing API call; no API, D1, pricing, bid, or cap semantics changed.
  • Focused TopNav/Territories verification passed 2 files / 15 tests with TypeScript. Vite build, brand audit, production controls 21/21 (123 assertions), docs build (10 internal + 2 client docs + index), and git diff --check passed. Two default-parallel full-suite reruns reached 784/785 and 783/785 before unrelated resource-contention timeouts; every named timeout passes in isolation. The required post-change-polish runner remains blocked before execution by Bun 1.3.0's existing top-level-return syntax error; a manual v60 token, motion/reduced-motion, and simplification pass was completed instead. This is local source evidence only, not hosted CI, staging, or a physical-iPhone retest.

Next up: independently review this exact local commit, then merge/stage normally before requesting a fresh physical-iPhone/Safari follow-up. No provider, D1, Stripe, deployment, push, PR, merge, or message action occurred.

2026-07-21 — PR #274/#275 exact-main protected-staging release evidence (staging; not production)

  • PR #274 merged normally as 7dda4f7efcdcd7ab6fbf07193cc5eec7fabdb433; PR #275 then merged normally as current main fe6ff71e26f915167db6ba4c89440a53e2af481e. Independent exact reviews returned READY with no P0–P3 findings. Combined deterministic source proof was 85 files / 782 tests, TypeScript, Vite production build, transparent-brand audit, production controls 21/21 (123 assertions), docs clean, and git diff --check.
  • Protected staging applied only 0039_package_readiness_v4.sql (migration receipt: /var/folders/q8/6s5j8ycx0m9b7zcgm3l40xkw0000gn/T/soldi-staging-migration-boundary-HcBtMj/migration-fe6ff71e26f915167db6ba4c89440a53e2af481e.json) and deployed the exact SHA (deployment receipt: /var/folders/q8/6s5j8ycx0m9b7zcgm3l40xkw0000gn/T/soldi-staging-deployment-receipt-1ovY6U/deploy-fe6ff71e26f915167db6ba4c89440a53e2af481e.json). Provider readback binds deployment 25bdefe6-0edd-41e7-98d3-08b6b0693a42, Worker cb6c6d2d-093f-4ec6-8267-e4d1d289c084, tag v60-fe6ff71e26f9-9980e7a81e06-c2ca28e8707c4cbbb0c292b0634da231, and assets SHA-256 8cb85a53f3c80c25ed8c3d61e463efb11c6ace59bcf23283d91285fade678dcd. Health was exact five times; served staging Stripe sandbox identity was exact acct_1TtjDjPuLV917S5K in test mode.
  • The first real v4 scheduler decision package-reserve-v4:staging:2026-06-22:2026-07-22 recorded demand/committed 0, supply 5, ready=1, reserve_satisfied. It was scheduler-produced: no manual readiness row and no wallet, Package, or lead mutation occurred.
  • Authenticated fairhomecash Chrome QA covered all six v60 buyer screens—Market, My Leads, Territories, Transactions/Activity, Billing, and Settings—at 1440x900, 390x844, and 320x844: no document overflow; primary phone controls at least 44px; five 49px bottom tabs; correct price colors; desktop bottom navigation hidden; and the Package panel says Package ready to start. The 320px My Leads tier row intentionally uses horizontal scrolling (288px client, 319px scroll) so Cold remains reachable. Zak received the exact link/SHA/version and copy boundary and was asked for a physical-iPhone pass.
  • Separate Fair Home Cash Stripe readback found sandbox acct_1TsllIR34twH5OTZ and live acct_1Tsll8J1YBgaOKuA; both are distinct from staging's older Soldi sandbox. The live account remains on Activate your account / Verify your business onboarding. No Stripe provider setting changed. Public production health is legacy (/api/v1/health 200 without SHA/version; /api/v1/health/stripe 404), and the source-only production plan receipt is /var/folders/q8/6s5j8ycx0m9b7zcgm3l40xkw0000gn/T/soldi-production-plan-mi9JZu/production-plan-fe6ff71e26f915167db6ba4c89440a53e2af481e.json (config 5a8126684eb8adde212365759da82702ccae75833e6e1693258db0bc7c35cbdc, assets 8cb85a53f3c80c25ed8c3d61e463efb11c6ace59bcf23283d91285fade678dcd, diff 9d23708444bd0340da9267e7e2ba3a1b428da6c310f442a97b9314421f21a603).

Next up: production remains HOLD pending fresh explicitly authorized production-D1 copy rehearsal through 00250039 plus Time Travel rollback and temporary-D1 deletion; Cameron's legal/business onboarding completion and explicit confirmation that the new FHC organization is canonical before production keys/webhook wiring; exact live Stripe/webhook proof; physical-iPhone acceptance; signed external acceptance; and action-time promotion authorization. Reference-only PR #270 remains unmerged. Ordinary UI defects are fix-forward only.

2026-07-21 — PR #275 exact-head mobile review repair (local; not deployed)

  • Terra/high reviewed exact PR #275 head ef56534e446d4d538afcc535714aec547ec8a1ac and found no backend, Stripe, pricing, or Package-semantic delta, but requested two P2 My Leads display corrections: the new mobile seller suffix rendered by default on desktop beside the existing Seller column, and the mobile Price cell's font-size:0 hid the amount while leaving only the Package badge visible.
  • The repair makes .ml-mobile-seller desktop-hidden and phone-visible, and renders the compact phone Price cell at 12px. Source assertions lock the desktop-hidden seller contract, visible phone price rule, and absence of the zero-font-size regression.
  • Focused exact repair proof passed 5 files / 44 tests, TypeScript, and git diff --check. This is local source evidence; independent exact-head rereview, hosted CI, authenticated staging, and physical-iPhone proof remain separate.

Next up: commit and push the repair, obtain the same reviewer's exact-head rereview and fresh hosted CI, then merge normally if clean.

2026-07-21 — Package v4 merged; mobile fidelity PR candidate ready

  • PR #274 passed hosted CI and independent Terra/high exact-head review with no P0–P3 findings, then merged normally as 7dda4f7efcdcd7ab6fbf07193cc5eec7fabdb433 (parents dda7d318682cc0350df0ec555d85b3e3c9ab201d and reviewed head dfb82bdcbfce039bc915d0479bdf0ab1da874f6d). Exact ancestry was verified after fetching origin/main.
  • The mobile branch already descends from the reviewed PR head, so its diff against merged main remains only the two mobile commits plus their additive proof documentation. No reimplementation, squash, or source conflict is required.

Next up: publish the ready mobile PR with killerabbasi requested, run independent exact-head UI review and hosted CI, merge normally, then deploy only the resulting exact main merge SHA to protected staging.

2026-07-21 — Combined Package v4 + Zak mobile fidelity candidate (local; not deployed)

  • Rebased the two mobile-fidelity commits onto exact reviewed Package v4 PR #274 head dfb82bdcbfce039bc915d0479bdf0ab1da874f6d. The resulting exact local head is 44ed7c1d8e8ae0f6d4409928577b3d0964446f58; the Package v4 migration/runtime/control history and both mobile commits remain distinct and attributable.
  • Resolved only the additive BUILD_LOG.md rebase conflict by retaining both workstream entries. No worker, migration, Package, Stripe, pricing, or copy semantics changed during the rebase.
  • Exact combined proof passed the complete deterministic app suite 85 files / 782 tests, TypeScript, Vite production build, transparent brand-asset audit, production controls 21/21 (123 assertions), docs build (10 internal + 2 client docs + index), and git diff --check. No provider, D1, Stripe, deployment, GitHub mobile PR, funded Package, or message action occurred.

Next up: merge independently reviewed PR #274 after hosted CI, publish this mobile branch as a separate ready PR with Zak requested, then deploy only the final normal-merge main SHA to protected staging for 0039, scheduler-produced v4 readiness, and authenticated desktop/phone QA.

2026-07-21 — Package readiness denominator v4 (local source candidate; not deployed)

  • Added forward-only 0039_package_readiness_v4.sql; it creates new v4 decision, state, and activation-reservation tables without copying or mutating the deployed v3 evidence. Package runtime authority, schema checks, billing/renewal reserve predicates, paid-cycle guard, and router eligibility/completion now accept only literal package-reserve-v4 / scheduled-package-readiness-v4 state.
  • Corrected the supply denominator to only PPC $250 investor candidates. Any missing or unparseable timestamp within that candidate set fails closed in both recomputation and the immediate pre-debit reservation predicate; noncandidate PPC rows remain retained and do not poison supply. SQLite regressions preserve the bad same-window v3 decision while allowing a corrected v4 ready decision, reject cross-environment/v3 reservation authority, and prove five candidates plus six noncandidate PPC rows returns 5 / reserve_satisfied.
  • Advanced protected staging and production controller inventory to exactly 39 files, 24 applied, and 15 pending through 0039; hostile partial, advanced, malformed, and action-time authorization gates remain. Focused Package SQLite/scheduler tests pass 5 files / 92 tests; staging control passes 60/60 (237 expectations) and production control 21/21 (123 assertions). The default parallel bun run verify encountered four asynchronous UI failures/timeouts under resource contention, so it is not recorded as green; the exact committed SHA passed the full app suite serially (85 files / 781 tests) plus TypeScript, Vite production build, brand audit, docs build (10 internal + 2 client docs + index), and diff hygiene. The four affected UI files also pass when rerun in isolation. No provider, D1, deploy, GitHub, message, or Package wallet action occurred.

2026-07-21 — Zak mobile fidelity pass 2 (local source candidate; not deployed)

  • Post-commit corrective pass: the first fidelity commit compacted several new phone controls below the locked 44px hit target. The local follow-up restores 44px minimum width/height for compact-shell balance/Add funds/account controls, Billing Manage cards and referral, My Leads stage/Call/search controls, and Territory top Add, bid/cap, weekly-cap, remove, county/state choice, and search controls. Density remains in typography and gaps, not shrunken touch boxes. Focused source tests passed 4 files / 38 tests; the one root verifier was not rerun after four unrelated UI failures/timeouts under concurrent load (81 files / 773 tests passed, including the repaired suite). This remains local source proof only.
  • Built directly above exact PR #273 head 57189577e0e2e5c6ad57d54bb0c74b00c032ee8e in an isolated worktree. The app-only pass adds persistent phone tabs for Market, My Leads, Territories, Activity, and Wallet; retains compact real-balance and Add funds header actions; and moves phone referral access into Wallet so it no longer consumes the shared utility row.
  • Market's canonical tier prices now carry their tier colors ($250 Hot orange, $150 Warm green, $90 Cold amber). My Leads suppresses page-header and desktop-only control overhead on phones, uses a denser row hierarchy, and adds a per-card stage sheet while retaining desktop select controls. Territories no longer displays raw internal IDs and its phone cards/sheet prioritize county/state, bid, cap, market context, and live position. Billing keeps Stripe, custom budget/cap, Package, and invoices intact while removing Manage-cards layout dead space and keeping Add funds primary.
  • Focused app UI coverage passed 7 files / 68 tests. Local source captures at 390×844 and 320×844 showed scrollWidth === viewport, five non-truncated bottom-tab labels with 49px targets, and the tier price colors. Those captures used a local mocked session/feed for geometry only; they are not hosted or payment-flow proof. The post-change polish helper remains syntactically blocked by its existing top-level return error, so the manual token/reduced-motion/simplification pass is recorded in platform-completion.md.

Next up: complete exact-candidate verification and normal review. Fresh authenticated hosted browser and physical iPhone/Safari acceptance still remain release gates; no provider, Stripe, deployment, merge, or message action occurred.

2026-07-21 — Package fulfillment readiness v3 (local source candidate; not deployed)

  • Added forward-only 0038_package_readiness_v3.sql: v2 readiness evidence remains immutable, while v3 decisions, state, and activation reservations are keyed to literal staging or production. Unknown/unset environments fail closed; a production decision cannot consume a staging state or reservation. Billing rechecks v3 readiness immediately before activation writes and wallet debit, and router eligibility/completion joins the current environment only.
  • Rendered protected staging with exactly one * * * * * readiness schedule and literal PACKAGE_READINESS_SCHEDULER_ENABLED=true. Production source declares the same variable as literal false; this is source capability only, not authorization to activate production Package routing. Do not manually insert a readiness/state row. The next safe step is an authorized staging migration/deploy, inspection of a real v3 decision, then a disposable-account funded Package activation/idempotency/My Leads proof.
  • Corrected the MVP delivery contract: Package routing and delivery records now use only in_app, and active/inactive Billing copy says that verified Hot leads land in My Leads. Removed the prior email/webhook/CSV claim; the mobile /leads label is now My Leads. No transport/provider was added and no copy claims one exists.
  • Focused Package/Billing/Router/MobileNav tests passed 6 files / 89 tests; staging controller/migration/authority/demo proof passed 60 tests / 237 expectations; the exact full app gate passed 85 files / 776 tests, TypeScript, Vite, and brand audit. The TopNav test was synchronized to its already-rendered My Leads link. Docs built 10 internal + 2 client docs + index and git diff --check passed. The mandatory UI polish runner remains blocked before execution by its existing top-level SyntaxError: Illegal return statement; Billing and MobileNav received manual v60-token/responsive/reduced-motion review. No provider, D1, Stripe, deployment, merge, or message occurred.
  • Integrated above merged V4 main fbb919b: production control now requires exact 0038 / 14-pending inventory and the reviewed one-minute staging schedule. Static staging receipts derive current config/migration/live-readback/provider digests; all pre-existing hostile partial/advanced/malformed inventory and action-time authorization checks remain. Focused production controls pass 21/21 (123 assertions).
  • Independent exact-head review caught that the shared production one-minute cron would still call the disabled readiness function and write an immutable disabled decision. The fix preserves renewal/allocation recovery on that shared cron but skips readiness recomputation entirely unless the literal environment-aware scheduler flag is enabled; a direct production regression proves no v3 readiness decision/state write SQL is prepared. The repaired exact candidate passes 85 files / 777 tests, TypeScript, Vite, brand audit, production controls 21/21 (123 assertions), docs build, and diff hygiene.
  • PR #273 merged normally as exact main dda7d318 and deployed to protected staging through only migration 0038; health and Stripe identity bind Worker version 11624327-bbdb-45d8-bae2-bccaffdfcede. The first real scheduled decision safely returned not-ready: five valid Hot/PPC investor rows were poisoned by six retained PPC rows at other prices or the retired Agent vertical. The fix-forward source removes that out-of-contract all-PPC poison query, retains strict demand/integer checks, and adds a mixed-PPC SQLite regression (3 files / 41 tests). No staging row was edited or manually inserted and no Package wallet mutation occurred.

Next up: independently review and merge the denominator repair, redeploy exact main, and wait for a safe scheduler-produced decision before the disposable funded Package lifecycle proof. Production remains HOLD until the candidate-bound data-safety and money-path evidence exists.

2026-07-21 — Production action-time authorization V4 (local control-only)

  • Current exact base is normal origin/main merge bfd335935de789bc7ef9da876443f7801651488b. The former V3 GitHub-review condition was mechanically impossible after that normal merge because GitHub can review a PR head but cannot attach the demanded V3 review to the post-merge candidate SHA.
  • production:promote now ends with the exact literal SOLDI_PRODUCTION_GO_V4, not pull/review IDs. After every rehearsal, rollback, staging/provider, Stripe exact-once, hosted QA, physical-iPhone, external-acceptance, expected-preflight, and pending-migration receipt has passed closed-schema validation, the controller mints a schema-4 authorization valid at most 15 minutes and no later than the earliest underlying 24-hour evidence expiry. It binds the exact candidate/config/assets/migration and canonical digest of all validated evidence, then validates again inside the maintenance fence before bookmark/migration.
  • V4 is explicitly an operator action-time confirmation, not an independent cryptographic approval. The fixed-key signed external-acceptance packet, real-production-copy rehearsal + temporary-D1 Time Travel rollback, expected retained-data preflight, maintenance fence, bookmark/migration proof, and no-automatic-restore policy are unchanged. github-approval.mjs is unreferenced by runtime and retained solely for historical parser coverage.
  • Independent review held first on a freshness time-of-check/time-of-use gap and current-document V3 contradictions, then held the first repair because a manually extended local expiresAt was not compared with the bound evidence clock. Validation now independently requires both now < evidenceExpiresAt and authorization.expiresAt <= evidenceExpiresAt, so inside-fence revalidation fails before bookmark even if the unsigned operator-local timestamp is altered. Current readiness/Roadmap describe V4 and 13 pending migrations through 0037; append-only historical V3 entries remain intact. The final corrected head passes 85 files / 773 tests, TypeScript, Vite, brand audit, and production controls 21/21 (123 assertions); docs build, diff hygiene, and exact-head rereview follow. No Cloudflare, D1, Stripe, GitHub, deployment, account, email, or message action occurred.

Next up: keep production HOLD until fresh exact-candidate staging/provider, Stripe replay, hosted six-screen, physical iPhone, signed external acceptance, and separately authorized real-production-copy rehearsal/rollback evidence exist. Only then may a named operator provide V4 at action time.

2026-07-21 — PR #269 exact-head review repair (local, exact-main candidate)

  • Preserved both normal PR #271 buyer-mobile history and PR #269 account-recovery history while moving the three recovery commits onto exact origin/main a0804f29e81d286bb9e322b18c9420c59e4d226b. No merge, deploy, provider, D1, account, email, or reviewer-state mutation occurred.
  • Corrected the staging-controller P1: tools/staging/migrate.mjs now imports canonical REQUIRED_SECRET_NAMES from tools/staging/control.mjs. tools/staging/migrate-input.test.mjs directly invokes only stagingMigrationInput, proves the validated input has the canonical five required secret names and exact 37-file inventory, and cannot reach authority/provider work.
  • Corrected the visible walkthrough spelling only: genericlygenerically. There is no UI behavior, status, screenshot, or product/runtime copy delta beyond that documentation-only typo.
  • Stabilized app/worker/auth-login.test.ts only: immediate same-user createSessionToken calls could share the same millisecond and therefore produce identical signed payloads/derived CSRF values. The fixture gives the deliberately stale token a +1ms issued time and asserts both session and CSRF tokens differ; production auth code and behavior are unchanged.
  • Exact-main evidence passed: direct migration-input 1/1, staging controller/authority/demo 60/60, recovery/auth/security/client 63/63, production controller 20/20 (112 assertions), docs build 10 internal + 2 client docs + index, and exact root bun run verify 85 files / 773 tests with TypeScript, Vite, brand audit, and production control green.

Next up: independent exact-head review, then separately authorized protected-staging migration/deployment receipts and hosted/browser/physical-iPhone evidence. Production remains HOLD.

2026-07-21 — Zak mobile polish (local, ready for review)

  • Exact base is current origin/main 0758d195260f041a59392ea30a193ec985987464; the bounded follow-up changes only buyer-route presentation and focused tests. No previews/, worker, auth/session, provider, D1, staging, or production files changed.
  • Read PR #270 body and exact preview-only head a29e9c74d27e8d62a5a8f3e6697d6e9a5e16a8f2 read-only as the current phone interaction/layout authority; it is not merged and its mock file is untouched.
  • Open Market now follows its dense phone-ledger direction: tier dot, city, readable tier/situation/county/freshness metadata, price, and independently visible 44px Buy target in a compact row.
  • My Leads now follows its no-filter-wall direction: Tier remains a one-handed rail, while one Stage control opens the responsive drawer as a phone bottom sheet and Package stays adjacent. The former per-row phone stage-chip rail is replaced by one full-width 44px native selector, so Under Contract/Closed/Dead cannot be clipped inside a 390px viewport. Desktop keeps the pre-existing status/package controls; behavior, counts, Package gating, and stage filtering are unchanged.
  • Transactions keeps the existing ledger hierarchy but uses a narrower phone grid, 44px date-range/Add-funds controls, and 44px inline refund/resend actions. Territory phone rows reserve a full bid row and Remove clearance at 320px; the county-picker result card and bottom-sheet action area are tighter without changing the county-only or 3 / 5 / 10 contracts.
  • Payment & Budget now keeps the three deposit choices in one touch-safe phone row above the full-width Add funds target, places custom budget, reset day, and Save in one reachable phone row, and collapses its real Package and Invoice sections behind 52px phone summaries. That turns the initial wallet/budget transaction path into the first screen instead of the staged base's 2570px page, without removing any control or changing integer-cents math, deposit bonuses, Stripe Checkout/portal wiring, or 44px transaction targets.
  • Correction to that phone-disclosure description: the first candidate only synchronized the disclosures when entering desktop, so a portrait → landscape → portrait transition could leave both open. BillingDisclosure now derives both disclosures from the current media-query result on every breakpoint event; a deterministic matchMedia regression covers mobile → desktop → mobile and verifies an in-place phone toggle still works. No Package, Invoice, Stripe, cents, backend, token, or visible-copy contract changed.
  • Follow-up evidence supersedes the preceding 82 / 748 count for this branch: focused Billing passed 2 files / 17 tests, the five changed buyer routes passed 5 files / 60 tests, and exact root bun run verify passed 82 files / 749 tests, TypeScript, Vite build index-C9Id425m.js, the brand audit, and production controls 17 / 100. No deploy, provider/D1/Stripe action, merge, or message occurred.
  • Fresh authenticated staging QA at exact base 0758d19 supplied two acceptance targets: clipped My Leads stage chips at 390x844 and a 2570px Billing page. This candidate addresses both in source, but no current-candidate authenticated browser session/screenshot exists. The direct current-source probe was discarded after proving localhost:5173 served another worktree; physical iPhone/Safari acceptance remains open.
  • The exact parallel root bun run verify completed but hit six unrelated UI loading timeouts (77/82 files, 742/748 tests). A retained sequential session then passed the complete app suite 82/82 files, 748/748 tests, followed by TypeScript, Vite build, brand audit, and root production controls 17/17. The mandated post-change workflow remains syntactically blocked by its existing top-level return; manual make-it-sexy/make-it-simpler review retained existing v60 tokens, reduced-motion behavior, and minimal page-scoped geometry.
  • Mobile-only visible copy delta: Stage is appended to the selected stage control and sheet rows; Tier, Status, and Delivery labels are no longer visually shown on phone; Payment & Budget adds Lead package / Compare ways to buy or manage your plan and Invoices / Downloads and wallet activity as collapsed phone summaries. It also adds the accessible group name Deposit amount. No product claim, price, tier, situation, legacy-surface, or desktop-visible v60 copy changed. Intentional #270 deviations: no five-tab mock navigation because the real six-route app includes Settings and current route/accessibility behavior; no fake Wallet/Territory data or altered Stripe/money paths; and real Package/Invoice controls are collapsed on phone, not omitted to force the mock's static zero-scroll claim. No merge, deploy, or message occurred.

Next up: PR #271 is ready with killerabbasi requested; after its normal merge, bind the merge SHA to fresh protected-staging authenticated browser screenshots and a physical iPhone/Safari retest before advancing any release gate.

2026-07-21 — Account recovery (local, ready for review)

  • Built from exact pre-merge origin/main 0758d195260f041a59392ea30a193ec985987464 without querying, resetting, merging, or deleting any real account, password, session, or D1 data. This source-only candidate adds actual account recovery rather than the prior support-only placeholder.
  • The Worker generates a random 256-bit capability, stores only its SHA-256 digest for 30 minutes, consumes it atomically, and updates users.password_changed_at on success so all earlier sessions are invalid. A reset does not create a replacement login session.
  • Valid recovery requests return the same immediate generic 202 before account lookup, token work, Resend I/O, or cleanup runs in executionCtx.waitUntil; email/IP limits use HMAC-derived scopes. Missing provider configuration creates no token, provider failure deletes the issued token, and logs contain only a fixed failure label plus HTTP status.
  • Resend delivery uses RESEND_API_KEY plus separate RESEND_PASSWORD_RESET_FROM=Soldi <account@notify.soldi.cc> bindings. The possibly Fair Home Cash-branded RESEND_DEFAULT_FROM is deliberately unused. The local source run sent no email and did not read or alter provider state.
  • Added /forgot-password and fragment-token /reset-password v60 pages. Both guarded client mutations preflight same-origin /auth/me before POST, preserving the existing origin/CSRF protection through the Safari missing-companion race.
  • Direct recovery tests cover hash-only storage, replay, expiry, enumeration, rate limits, missing provider, Resend success/failure, delivery cleanup, redacted logs, immediate public response/background completion, and client preflight ordering. The compact source capture proves layout/copy only, not hosted delivery.
  • The mandated post-change polish runner remains blocked by its existing top-level SyntaxError: Illegal return statement; recovery UI was manually reviewed for v60 tokens and reduced-motion behavior. No deploy or provider/data mutation occurred.

Next up: rebase this candidate onto the current normal main merge, then under separate explicit deployment authorization set RESEND_API_KEY for both Worker environments and perform the staging-only delivered-email, replay/expiry, session-revocation, and physical Safari acceptance.

2026-07-21 — Buyer mobile-responsive remediation (local, ready for review)

  • Rebased the isolated buyer-UI branch onto the normal auth-merged main SHA 6e27a0480746a013621ddf61b280d45c759c64b9; no auth, session, login, worker, provider, staging, or production files changed in this follow-up.
  • The evidence-backed changes keep the mobile utility/referral row within 320px without a help-launcher collision, make Add funds and mobile drawer rows at least 44px, make Territory package choices and weekly-cap controls at least 44px, and contain wide Billing invoice tables in their own horizontal scroll region rather than clipping the document.
  • Rebased changed-surface Vitest passed (8 files / 50 tests locally; an independent root rerun reported 8 files / 46 tests for its selected surface). A prior idle full bun run verify passed: 82 app files / 747 tests, TypeScript, production Vite build, brand audit, production controls 17 / 100, and repository checks. A later concurrent root full run reached 79/82 files / 744/747 tests before three unrelated five-second UI-test timeouts (BuyerScreens preference prefill, Territory modal minimum bid, Billing Package activation); without changing timeouts, isolated recovery passed those exact files 3 / 28. Treat that later run as load-induced and do not substitute it for the already-valid full proof. The configured post-change polish workflow could not run because .claude/workflows/post-change-polish.js throws top-level SyntaxError: Illegal return statement; independent make-it-sexy review found no token/copy drift and make-it-simpler found the patch minimal.
  • Current-source local Chrome checks at exact 390x844 and 320x844 report no document overflow (scrollWidth === viewport), a 44px help launcher, and an in-flow referral/help utility row. Console output was empty and all loaded application requests were successful; the aborted initial /auth/me request was superseded by a 200 retry. Local existing-account authentication remains blocked by the app's intentional CSRF-origin policy, so these are source-shell checks rather than authenticated buyer-route acceptance.
  • Product copy delta: none. The prior protected-staging/mobile capture and 998186e receipts are historical after both auth and this UI change; no deck screenshot is presented as current authenticated-candidate proof. No merge or deploy occurred.

Next up: merge the reviewed PR normally, bind its exact merge SHA to fresh protected-staging authenticated six-screen browser checks, then repeat the complete physical iPhone/Safari path (dynamic toolbar, keyboard, safe area, existing-account login, funding/budget, Territory modal/drawer, and invoice table) before advancing any release gate.

2026-07-21 — Existing-account login repair (local, ready for review)

  • Zak's physical-iPhone report found a distinct gap from the fresh-signup path: his existing staging account correctly returns email_taken on registration, but its login reaches the generic protected failure. No real account, password, session, or D1 row was inspected, reset, or deleted.
  • The repair preserves exact-origin and session-bound login CSRF. Before the guarded login POST, the SPA makes same-origin GET /auth/me; a valid old soldi_session can thereby receive a replacement readable soldi_csrf companion instead of weakening the worker guard. Direct route coverage first proves a valid old session plus stale CSRF remains 403 csrf_token_rejected, then proves /auth/me refresh and authenticated login succeeds.
  • verifyPassword now safely rejects malformed/partial PBKDF2 fields (invalid base64, unexpected lengths, or unsafe iteration count) as false. The login route therefore returns the existing generic 401 invalid_credentials response, emits no auth cookies, and never exposes parser/WebCrypto failures or account-state detail.
  • Source verification passed focused auth/session/security 4 files / 44 tests and the full app Vitest suite in four executable shards: 82 files / 746 tests. TypeScript, production Vite build, brand audit, production-control 17 tests / 100 assertions, docs build (10 internal + 2 client docs + index), readiness-JSON parsing, and git diff --check also passed. Expected forced rollback/compensation and jsdom diagnostics remain test fixtures, not failures.
  • Historical 008119d/staging records are now explicit: they prove the fresh-account/browser path and the now-closed replay retry (evt_1TvN7mPuLV917S5KpzdFdzuV200, one event/claim/immutable ledger row; receipt 3a8c11cfc40d35733bea6d8c841e25eb41fdb2a8714e4db04c621475174b57fd) but cannot authorize this next runtime merge. Zak's approval is good to go; a later controller must bind it mechanically to new candidate evidence. The readiness JSON has no current candidate. Product UI copy delta: none; walkthrough and readiness wording now disclose the existing-account gap and fresh proof requirement. No deploy, provider, or staging mutation occurred.

Next up: merge the reviewed PR normally, then make its exact merge SHA the new candidate; run protected-staging migration/deploy and existing-account browser/iPhone proof before treating authentication or any prior staging receipt as current.

2026-07-20 — Fresh-signup repair staged and hosted new-account QA

  • PR #264 merged normally as exact two-parent main SHA 008119d88aee92bcd4db6be19c1275ff1ece54c5 after green GitHub CI and final Terra/high READY review. The source gate remained 81 files / 743 tests, TypeScript, Vite, brand audit, production controls 17 / 100, docs build, and diff hygiene.
  • Cloudflare authority initially failed closed at staging_authority_routes_failed. The already-persisted master-camo-dev-workers-token was the actual caller; it received only a soldi.cc policy for Workers Routes, DNS, and Zone read/write. No secret was copied, rotated, printed, or written to a temporary file.
  • bun run staging:migrate minted a retained-data-safe no-op receipt through 0036 with no pending/applied migrations and no D1 mutation. Receipt-bound bun run staging:deploy then published deployment 9e784f30-33a7-4223-89aa-debe717b8682, Worker version fad2c237-5465-496e-ab67-0d1b6b0db92a, tag v60-008119d88aee-a87e093d2375-3f2570bcf95b4d898e758e4cf50ceb45, and assets SHA-256 bd215b5b9c8a3621444bf0ba46f0be44e8d480ddbfd57b991a19ab326637240e at staging.soldi.cc.
  • Connected FHC Chrome QA signed out of the prior seeded account and created a unique staging-only user without ?demo=1. Registration survived reload; all six setup steps plus final completion saved; Settings returned the new identity; Refunds rendered the honest no-requests state; and Add Funds created a $1,000 Checkout on exact sandbox account acct_1TtjDjPuLV917S5K.
  • The authorized Stripe test card completed that Checkout. The signed webhook path credited the wallet from 50,000 to 150,000 cents; D1 records one processed_stripe_events row, one stripe_economic_claims row, and one immutable stripe_verified_funding ledger entry for 100,000 purchased cents and zero promotional cents. Explicit provider-event resend is still open because the locally authenticated Stripe CLI is expired and the connected dashboard session cannot access acct_1Ttj…; no acceptance receipt claims the replay check yet.
  • Exact 390x844 Billing, Settings, and Refunds checks each reported scrollWidth === clientWidth === 390 and zero application console errors. Billing's repaired layout was visually inspected. This is hosted browser proof, not a physical iPhone/Safari receipt.
  • Exact-candidate production planning also completed without remote mutation: config SHA-256 47f0cb4d90cb5b3790bf2abe03374ce0deb2788ec94ffc598874e2387ee97eba, assets SHA-256 bd215b5b9c8a3621444bf0ba46f0be44e8d480ddbfd57b991a19ab326637240e, and redacted-diff SHA-256 095ea307e28b66f3b2c78e6e7f4b87e0e5f808b2570106dc45b1b5e41ed9ccc7.
  • Public copy delta: NONE. Production remains HOLD for explicit Stripe idempotency replay, real-production-copy migration rehearsal and tested rollback, Zak's exact-iOS physical retest, signed external acceptance, retained-data comparison, GitHub V3 approval, and SOLDI_PRODUCTION_GO_V3.

Next up: Zak repeats the brand-new-account path on his physical iPhone and reports exact iOS plus checklist results. In parallel, perform a controlled resend of the already-processed signed Stripe event from the correct sandbox account, then run the separately authorized production export → temporary-D1 create/import/migrate/Time-Travel restore/verify/delete rehearsal rather than stopping work on those independent gates.

2026-07-20 — Physical-iPhone fresh-signup acceptance failed; production remains held

  • Zak's later iPhone 15 test supersedes the earlier positive 390px report below. He registered a brand-new personal account rather than using the seeded demo flow; setup-quiz save, Add funds, refund/status loading, and Settings data failed on iOS Safari.
  • The demo-account and automated responsive passes remain useful UI evidence but do not prove registration cookie persistence, new-account provisioning, zero-row states, or authenticated mutations after a fresh signup. Physical-iPhone and external acceptance are open/failed, not cleared.
  • Repair is isolated on branch codex/fresh-signup-ios-fix-20260720 from documentation-only main f72036de31722ff6d10022073666534fed18f836. Protected staging still serves application SHA 6a69948a28fec11e6369bda4d60274fa8c0976a1; production was not promoted.
  • The repair changes production cookies from SameSite=None; Secure to first-party SameSite=Lax; Secure, requires login/registration to confirm cookie-backed /auth/me server truth before exposing authenticated UI, makes that response explicitly private/no-store, and fences bootstrap/refresh/logout/unmount races. New Vitest coverage exercises fresh registration, stale bootstrap, logout authority, and unmount cleanup.
  • The new-account database transaction was already atomic; no seed or synthetic empty-state workaround was added. The shared failure shape was the browser session handoff, which the seeded demo path could not expose.
  • Three independent Terra/high tmx review lanes checked correctness, reuse, behavioral UI polish, and simplification. The final exact-diff rereview returned READY with focused auth/session proof 44 / 44; public-copy delta is none.
  • Frozen install and the final release gate passed: TypeScript, production Vite build, brand audit, 81 app test files / 743 tests, production controls 17 tests / 100 assertions, recursive docs build 10 internal + 2 client docs + index, readiness-JSON parse, and diff hygiene.
  • Zak was texted at +17739974600 only, told that the prior acceptance interpretation was withdrawn, and asked for the exact iOS version. He will receive a new exact-SHA/version staging link only after the fresh-account repair and hosted QA are complete.

Next up: land the reviewed repair through a ready PR, deploy the exact normal merge to protected staging, run a brand-new-account hosted journey, and require another brand-new iPhone signup pass before reopening external acceptance or V3 promotion sequencing. The Stripe provider receipt and real-production-copy rehearsal/rollback remain separate exact-candidate gates.

2026-07-20 — Zak physical-iPhone acceptance reconciled to exact current staging

  • Fresh fetch proved clean exact origin/main 6a69948a28fec11e6369bda4d60274fa8c0976a1. Live staging.soldi.cc health returns that exact SHA and Worker version 91cb1189-bb6c-432c-938a-4c2624f347dd; Stripe health returns test mode and sandbox account acct_1TtjDjPuLV917S5K.
  • The current protected deployment is e29aa900-9aae-4021-b123-2abcf2600522 with assets SHA-256 4528644d752255131db2796138209f35a5162d46d639af371c7c1b2b2e11669f. The receipt-bound staging migration remained a no-op through 0036; no staging schema/data mutation occurred in this reconciliation.
  • Zak reported a clean physical-iPhone 390px pass for the six screens, test purchase, lead drawer, and tap-to-call. This records stakeholder visual/interaction acceptance from his side. The schema-1 gate remains open until he supplies the exact approved iPhone model, exact iOS version, and explicit all-pass confirmation for login, wallet-funding, market-purchase, territory-package-routing, payment-budget, and settings, and the closed content-bound device-session artifact/receipt is generated and validated.
  • Zak's statement that external acceptance is clear "from my side" is not substituted for the source-required fixed-key schema-3 Ed25519 attestation. He committed to paste SOLDI_PRODUCTION_GO_V3 same-day after receiving the exact-serving-SHA production-go packet.
  • The authenticated fairhomecash.com Chrome profile is prepared at the exact $1,000 staging sandbox funding action. No Checkout session, card submission, wallet credit, or provider mutation has occurred in this reconciliation.
  • Canonical readiness, JSON state, roadmap, walkthrough, and the living implementation note now name 6a69948a… / e29aa900… / 91cb1189… rather than stale candidate identifiers. Production remains HOLD.
  • Verification passed: frozen install unchanged; TypeScript; Vite production build; brand audit; 80 app test files / 739 tests; production controls 17 tests / 100 assertions; recursive docs build 10 internal + 2 client docs + index; JSON parse and git diff --check.

Next up: after owner action-time confirmation, complete the Stripe Checkout/signed-webhook/typed-ledger/idempotency receipt. Separately authorize the production D1 export plus disposable D1 create/import/migrate/restore/delete rehearsal, then finish the physical/external receipts and send Zak the bound V3 packet.

2026-07-19 — Mobile Billing merged and live on protected staging

  • PR #261 passed GitHub CI with Zak requested and merged normally as exact c579b8181f9fb7defda11e649906aee6925d5f45 (parents a120d715d517343a12c0ffe3da56f6a8036e9eee and 024ff759d1859019d323ef5bf8795193e61d9c03).
  • The authorized fairhomecash.com Chrome profile rolled camo-soldi-dns-key; account-owned verification and fixed-target account/zone/routes/domain/D1 preflight passed. The secret stayed mode 0600 in /private/tmp for this bounded run and is deleted afterward, per owner direction.
  • bun run staging:migrate proved all 36 migrations through 0036_investor_only_market.sql already applied, created the required Time Travel bookmark, and reported plannedPending: [], appliedThisRun: [], noOp: true, remoteMutation: false. Private migration receipt SHA-256: f28f92446dcb39197b2f169294f5f7f619803b342380d77c6315c6d76743c091.
  • Receipt-bound bun run staging:deploy created deployment 97388909-09ef-4bec-8849-a4f6968734ec, Worker version 603962af-92a0-4f83-9394-920c989eed5a, version tag v60-c579b8181f9f-3dedd61b1353-0915d45499f14705b1cce745601e13dd, and assets SHA-256 4528644d752255131db2796138209f35a5162d46d639af371c7c1b2b2e11669f. Deployment receipt SHA-256: 7c6113f4040f0c94dd9ba5c1218800462d370f87ef5e5ce5442ff01099945ff5.
  • Staging health binds exact SHA/version/environment. Stripe health binds the same SHA/version, test mode, and account acct_1TtjDjPuLV917S5K.
  • Authenticated Chrome and independent Terra/high both returned READY at exact 390x844 and 375x812: no horizontal overflow, interactive overlap, undersized required control, console error, or failed application request. Package selection enabled Add funds; a budget preset updated the editor; no financial/card/budget submission occurred. Screenshot: /private/tmp/soldi-staging-billing-390x844-c579b818.png.
  • docs.soldi.cc deployed as version 9d8ceab0-3cde-4f94-8de2-7aa57a687cea; hosted screenshot bytes match the exact local artifact. Visible public-copy delta is none; accessibility-copy delta remains the current-section announcement.
  • Production runtime was not promoted. UI-bug tolerance does not waive the real-production-copy rehearsal, tested rollback, hosted Stripe ledger journey, physical-iPhone, external acceptance, retained-data comparison, Zak V3 approval, or SOLDI_PRODUCTION_GO_V3 gates.

Next up: merge this receipt correction, redeploy docs, then execute the production-copy rehearsal/rollback and physical-iPhone evidence chain before the V3 production decision.

2026-07-19 — Mobile Billing overlap and clipping repair (local candidate)

  • An owner-supplied 390x844 staging screenshot falsified the prior mobile pass: clean document width did not detect the fixed support launcher covering the $20,000 budget preset, truncated Payment & Budget route context, or cramped desktop-shaped funding/budget controls.
  • The bounded repair starts from clean canonical origin/main a120d715d517343a12c0ffe3da56f6a8036e9eee. At phone width the redundant current-page Add funds header CTA is hidden, the full active route label fits, funding choices use a balanced two-column/full-width composition, budget presets use three equal 44px targets, the editor becomes two fields plus a full-width Save, and Manage cards clears the control grid.
  • The closed mobile support launcher is now an in-flow 44px utility-row button instead of a content-obscuring fixed overlay. Opening support still presents the support panel; desktop retains the fixed launcher.
  • The reusable UI validator now supports required-count no-overlap, no-clipped-text, and center-hit-targets assertions and includes both 375x812 and the exact reported 390x844 Billing viewports, preventing the earlier vacuous width-only pass.
  • Focused Vitest is green at 4 files / 23 tests. Local Chrome DevTools proof at both phone sizes recorded scrollWidth === innerWidth, full untruncated route text, one visible support target, zero support/control intersections, zero blocked Billing target centers, zero clipped named controls, and zero error-console output. Final screenshot: docs/shots/v60-payment-budget-mobile-20260719.png; prior capture preserved under docs/shots/before/.
  • Full verification initially exposed an accidental control-test coupling: the checked-in fixed-key Ed25519 signature included the mutable live app/dist digest, so any valid UI rebuild failed CI despite the operational verifier behaving correctly. The positive signature vector is now immutable, current app assets remain separately bound through the staging deploy test, and the real wrapper rejects an unsigned mutable candidate before any provider call. No verifier override was added and run.mjs cannot import the test-only post-validation orchestration seam.
  • Final local verification passed TypeScript, Vite production build, brand audit, 80 app test files / 739 tests, production controls 17 tests / 100 assertions, recursive docs build (10 internal + 2 client docs + index), and git diff --check. Terra/high returned READY for both the final mobile/UI evidence and the production-control decoupling, with no actionable P0–P2 findings.
  • Visible public-copy delta is none. Accessibility-copy delta: the navigation trigger now announces its current section. No provider, D1, Stripe, staging, production, or messaging mutation occurred in this local slice.

Next up: complete full root/docs verification and independent exact-diff review, then open the ready PR with Zak requested. After normal merge, mint a fresh exact-head staging migration/deploy receipt and repeat authenticated hosted 390x844 proof before any production decision.

2026-07-19 — exact current main live on protected staging

  • Freshly fetched origin/main and the clean deployment worktree both resolved to exact 90d35121e963747383d250bb04393edbb0d0fd07. The fixed-target Cloudflare credential passed exact account authority after rotation; no secret was printed or committed.
  • bun run staging:migrate proved all migrations through 0036_investor_only_market.sql already applied on soldi-staging, retained scalars unchanged, plannedPending: [], appliedThisRun: [], noOp: true, and no D1 schema/data mutation. The controller still created its required Time Travel safety bookmark. Its private receipt SHA-256 is 21e308b50d8497b5f16d320b79f17958b1e3f478f30b56470c07c8a9d34d5f4f.
  • Receipt-bound bun run staging:deploy created deployment a35ff8a6-ac73-42fc-a531-8a32fc02cd9d, Worker version fc7ac530-7269-4b00-a2c6-099c20625002, release tag v60-90d35121e963-4a71ef193c13-0e4e4b4db5b846cdabbd3fe0e30d53a4, and assets SHA-256 f56c593c631e603fea9260cab594b5f51b4c39330287705d73f669441141dd90. Deployment receipt SHA-256 is 055f5a882bb5da54a9f799c819753b44a7c3626c81b06264a724eb77c3736157.
  • Staging health binds the exact environment/SHA/version. Stripe health binds the same SHA/version, test mode, and Soldi sandbox account acct_1TtjDjPuLV917S5K. The demo-seed dry-run refused demo_seed_fixture_has_economic_history; no fixture apply/cleanup followed.
  • Independent Terra/high Chrome DevTools QA saved exact 1440x900 and 390x844 staging/production captures. Both origins passed Soldi branding, Open Market, removed-cruft, and page-level overflow checks. Staging unauthenticated /market resolves to /; production mobile retains contained horizontal scrollers without document overflow. Receipt: /tmp/soldi-tmx-hosted-visual-qa-20260719.md.
  • Root verification passed 81 files / 740 tests, TypeScript, Vite production build, brand audit, and production controls 15 tests / 120 assertions. Public-copy delta is none.
  • Production runtime was not promoted. The already-approved static brand release remains healthy at app.soldi.cc; full runtime stays HOLD for the real-production-copy rehearsal, tested Time Travel rollback, authenticated Stripe and hosted journey proof, physical iPhone, external acceptance, retained-data comparison, Zak V3 approval, and SOLDI_PRODUCTION_GO_V3.

Next up: merge this receipt documentation with Zak requested, deploy docs, then complete the remaining production V3 evidence without the generic app deploy path. Persist the rotated Cloudflare token into its approved 1Password item and remove the temporary protected copy after readback.

2026-07-19 — hostile staging migration-controller remediation (source-only)

  • The fixed external-acceptance verifier was rotated to key ID soldi-production-external-acceptance-v2 after the prior temporary private key proved unavailable. A deterministic schema-3 fixture now uses a static signature verified by the fixed checked-in public key; executable validation accepts no verifier-key override. The matching private half is mode 0600 outside the repository and must be transferred to an approved 1Password item, read back, and removed from temporary storage before any real acceptance or V3 request. Until then production remains HOLD.
  • The final hostile rereviews found the installed-toolchain escape in both .bin/wrangler consumers: each was hashed/executed without proving its symlink target remained in the frozen snapshot. Migration and deploy now recursively validate the installed tree while allowing only contained symlinks, resolve Wrangler to a regular executable inside the snapshot, and reject launcher or dependency escapes before bookmark, D1 readback/mutation, or upload. The active production runbook now names the required v2 acceptance key and its custody HOLD; the CLI emits unsigned canonical bytes without embedding private-key operating instructions.
  • Completed the uncommitted controller remediation without changing application/UI/public copy. staging:deploy validates local evidence, runs fixed-target authority preflight before snapshot/install/build, then obtains fresh fixed-target D1 migration inventory plus retained-scalar readback immediately before upload. The live readback is the deploy-time safety authority; the private migration receipt SHA-256 is an audit binding, not provider attestation.
  • Schema-3 deployment evidence now closes and recursively canonical-JSON hashes migrationReceiptSha256 and migrationLiveReadbackSha256; both feed the provider release digest, so stale/forged receipt identity or altered live response hashes/semantic values fail closed. Extracted Git source is fenced before install and app/dist after build, while valid installed-dependency symlinks are deliberately not rejected by a post-install whole-snapshot walk.
  • Migration preparation validates prospective success before cleanup, then removes and verifies the disposable snapshot before it writes or exposes success. Forced cleanup failure yields only a secret-free cleanup-failed failure receipt and no success callback. Local negative tests cover preflight order, receipt/live-D1 drift, digest alteration, source/asset symlinks, installed-dependency symlink tolerance, and cleanup failure.
  • Validation passed: bun run test:staging 58 tests / 230 assertions, bun run test:production-control 15 tests / 120 assertions, and bun run verify 81 app test files / 740 tests plus the same production-control suite; bun run build:docs produced 10 internal + 2 client docs + index. git diff --check passed. The scoped secret-shape scan found only deliberately rejected fixture strings, never credential material.
  • This is local source/test proof only: no Cloudflare/provider, D1, migration, staging deployment, hosted acceptance, production action, commit, push, PR, or merge occurred. Public-copy delta is none; production remains HOLD.

Next up: retain this uncommitted exact diff for independent review, then obtain separately authorized final-candidate provider/readback/hosted evidence.

2026-07-19 — final social-brand refresh combined with release controls (source-only)

  • Verified the downloaded transparent logo byte-matches canonical app/public/brand/soldi-logo.png at SHA-256 30adbc8f75f5bf1377c3f7b1714be1ae505a9d43dc3b9113ff92c805f31bd630; the corrected favicon ZIP-derived ICO/PNG/Apple/PWA family and all app logo paths are unchanged.
  • Used the four new owner references to generate four text-free background directions, selected the neutral dark marketplace/grid/house signal, and produced visually inspected opaque 1200x630 and 1200x1200 finals. The exact transparent wordmark and existing Exclusive Seller Lead Marketplace descriptor were overlaid deterministically, so public-copy delta is none.
  • Added app/brand-source/social/ as immutable source authority. brand:generate byte-copies approved composites into public deploy paths instead of re-rendering with machine-specific fonts; the brand audit locks four source hashes, source/deploy equality, dimensions/opacity, metadata order, and ?v=20260719-2. Raw source plates remain outside dist.
  • Merged source-only production evidence hardening f06959de58f39aadbd0fda7bfb22c4fe84b68170 above PR #253's merged-main authority 4b541310b178845af9a62b27b02d1b9521dca037, creating one combined review branch. Full root verification passes 81 files / 740 tests, TypeScript, Vite production build, brand audit, and production control 12 tests / 60 assertions; staging control passes 12 tests / 51 assertions and docs build produces 10 internal + 2 client docs + index.
  • No TSX/UI layout changed, so the mandatory UI polish workflow is not applicable. The walkthrough decisions are updated without recapturing app screenshots because the rendered application screens are byte-unchanged. No provider, D1, Stripe, staging, crawler-cache, or production mutation occurred.

Next up: independent exact-head source/browser review, one ready PR with Zak requested, then normal merge. Only that future merge SHA may receive fresh rehearsal/rollback, protected-staging, Stripe, hosted/crawler, physical-iPhone, external V3, and production receipts; production remains HOLD.

2026-07-19 — P1 final production-control evidence hardening (source-only)

  • Hardened production:promote to require, before snapshot, fence, bookmark, migration, or production provider work, a schema-3 protected-staging deployment receipt plus separate exact-account Stripe and hosted-QA receipts. The staging validator/revalidator is reused rather than copied: it binds soldi-staging, staging.soldi.cc, isolated D1, exact candidate tree/assets/migrations, version/deployment, required secret names, zero schedules, disabled workers.dev/previews, and exact custom domain.
  • Stripe evidence is no longer a generic pass boolean: it requires sandbox acct_1TtjDjPuLV917S5K, Checkout/payment-intent and signed webhook IDs, typed stripe_funding ledger ID, exact safe-integer cents arithmetic, explicit replay with zero duplicate ledger rows, and all named checks. Hosted QA now requires desktop and exact 390x844 results for six named routes with zero overflow, console/page errors, and failed HTTP requests. Physical-iPhone and external acceptance must share the exact staging version and deployment; external schema 2 canonically binds all four receipt hashes while the 13-line V3 review stays unchanged.
  • Focused source proof: bun test tools/production/control.test.mjs passed 12 tests / 60 assertions and bun test tools/staging/control.test.mjs passed 12 tests / 51 assertions after a production build. The test fixture covers a complete valid receipt chain plus missing/malformed/stale linkage, wrong account/version/deployment, replay failure, secret-field rejection, incomplete/erroring QA, digest tamper, and failed staging live revalidation before production calls.
  • Corrected the runbook’s stale rehearsal schema 3 / rollback schema 1 descriptions to schema 4 / schema 2 and documented the fixed ten-argument private input order. No app/UI copy, migration, provider, browser, Stripe, D1, messaging, staging, or production mutation occurred; public-copy delta is none.

Next up: exact-head review and normal merge of the control hardening. A future final main merge must still produce every fresh private receipt and V3 approval before promotion; production remains HOLD.

2026-07-19 — final social branding live without v60 runtime promotion

  • Ready PR #257 merged into exact production lineage as 55efa35922e9df2be159e0de28587f8e90ef386b after exact-head Terra/high static-only GO. The upload changed exactly /index.html, /brand/soldi-social-card.png, and /brand/soldi-social-square.png; no Worker, migration, D1, Stripe, route, cron, favicon, logo, manifest, JS, or CSS source changed.
  • Cloudflare version 36200b71-70b9-411d-b0b0-04f7d9ef4243, deployment a4080af8-9102-4906-a3a1-5f2c33b2f981 serves the seven v=20260719-2 metadata references. Ordinary/Facebook/Twitter/Slack HTML parity, source-equal 1200x630/1200x1200 PNGs, transparent live logo/favicon, unchanged bundle hashes, provider topology, cron, and /api/v1/health pass.
  • Desktop and 390x844 screenshots were inspected; the mobile Market list remains within the page and exposes its wider table through overflow-x:auto. Public-copy delta is none. This static release satisfies no full-v60 promotion gate; production remains HOLD for the exact final candidate's rehearsal, rollback, protected staging, Stripe, physical-iPhone, external acceptance, Zak approval, and SOLDI_PRODUCTION_GO_V3 receipts.

Next up: mint the full V3 receipt chain for the final normal main merge; do not invoke the generic app deploy or reuse these branding receipts as runtime-promotion authority.

2026-07-19 — buyer iteration merged into the final release PR

  • PR #254 final head d5be95f8eae34cd9a99b441bd90133fda7c9e191 repaired the five-market/Illinois Package-routing P1 and merged normally into PR #253 as 3c97dc29f8be0080387a098f1d2d2742539f8faf (parents 2ebc53a and d5be95f).
  • Verification passed focused 2 files / 42 tests, full app 81 files / 740 tests, TypeScript, production Vite build, final Sol/medium review with no P0–P2, and an isolated true 390x844 touch/iPhone-UA browser run across eight mobile/desktop journeys. The run recorded zero horizontal overflow, console/page errors, and HTTP >=400 responses.
  • This follow-up changes only launch-control documentation, including the walkthrough's release-status decisions. No screenshot was recaptured because the application UI and its existing acceptance captures are unchanged. Earlier July migration-rehearsal, rollback, staging, and Stripe receipts remain historical but are stale for the final production candidate. That candidate is created only by PR #253's future normal merge to fresh origin/main.
  • The first independent Sol/medium control review correctly held the documentation successor: the canonical current-state table still mentioned PR #196/e97cfd3 as operative, V1 as conditionally requestable, and only three hard gates. The repair makes all those references historical and requires the full V3 gate set; no application or provider state changed.
  • The bounded rereview then found two remaining control-only gaps: the operative sequence still named PR #196, and the JSON omitted explicit external-acceptance, retained-data-comparison, Zak-approved-V3, and V3-only-token gates. The final correction moves the sequence to PR #253 and makes those states first-class while marking old eaf68cc provider/fixture receipts historical.
  • The current table and JSON now also label the isolated backend, provider, demo-seed, and Stripe proofs historical, with exact final-candidate reruns open. This prevents a passing July receipt from being mistaken for a current promotion input.
  • Closed old PR #180 as superseded by #253; its selectively harvested payment/import/refund/staging semantics remain in the additive v60 train, but its older UI shell and launch authority will not merge. The canonical order now mints the two-parent main candidate first, then performs rehearsal/rollback, protected-staging reseed/Stripe/hosted/physical/external proof, V3 approval, and production promotion for that one SHA.

Next up: rerun CI and exact-head review on the documentation successor, merge PR #253 normally, then create fresh final-SHA receipts for the 12-migration real-production-copy rehearsal, Time Travel rollback, protected staging, physical iPhone, external acceptance, and V3 approval. Production remains HOLD.

2026-07-18 — supplied transparent favicon pack (ready source; not deployed)

  • Replaced the earlier opaque small-icon family with the exact supplied files from ~/Downloads/soldi-brand-assets/soldi-favicon.zip. The active ICO, 16/32/48 PNG, Apple-touch, and 192/512 PWA outputs contain real zero-alpha pixels; the generic MyWebSite manifest was excluded.
  • The audit now binds every direct deploy output to the checked-in source bytes and compares generated 16/32/48 PNGs against decoded source-ICO RGBA pixels. Four adversarial fixture tests prove rejection of a recolored PWA icon, a different valid transparent ICO, and a modified ICO-derived child PNG, while brand:favicon remains deterministic without social-card inputs.
  • Local verification passed 80 test files / 730 tests, TypeScript, Vite build, pre/post-build brand audit, and diff hygiene. No TSX changed, so the UI polish workflow was not applicable; the walkthrough layout and screenshots remain current.
  • Public-copy delta is none. This source follow-up does not change the production JS/CSS bundle, money path, database, API behavior, or any release gate. The retained-production rehearsal, tested Time Travel rollback, and physical-iPhone pass remain mandatory before any SOLDI_PRODUCTION_GO_V1 request or full v60 promotion.

Next up: final exact-patch review, ready PR with Zak requested, merge after CI, then a static-only hosted favicon refresh that preserves the current production runtime. Full v60 promotion remains separately held.

Production receipt

  • PR #250 passed hosted CI and merged as d1bc152828fb784a324c5514c819b0ba61b68226. Exact production-lineage hotfix 9baf86f deployed as Worker version 62d84152-c5bf-4b8b-adfc-5c49022fed1a, deployment cb1e573b-ffae-48d4-b9e7-6fd387c4370d.
  • Hosted ordinary/Facebook/Twitter HTML is byte-identical and advertises v=20260719. Every active ICO/PNG/Apple/PWA/manifest byte matches source, MIME/dimensions pass, and every icon has real transparent pixels. The manifest has no generic identity or unsafe maskable claim.
  • Production application JS/CSS remain exact 2770c9f4…671e / 35857dc8…cdb; app/src, app/worker, Wrangler config, D1, Durable Object bindings, cron, and four secret names are unchanged. Health returns 200.
  • Zak received PR #250, exact head, no-copy-delta, verification, and the unchanged three production-go gates. This receipt still does not authorize full v60 promotion.

2026-07-18 — Soldi digital branding live as static-only production hotfix

  • Production before release was exact July 9 source 04728d2ee4aa553ddf79a86a96f62eba9404847f, Worker version 55190601-0e74-406f-aee1-4f0bda417147, JS /assets/index-CU_EN45X.js, CSS /assets/index-BIrG5Bbu.css, and no Open Graph metadata. Rebuilding that source reproduced the served HTML and bundle names exactly.
  • Full merged main was not uploaded: remote readback found 12 unapplied production D1 migrations (0025 through 0036). Instead, exact hotfix 65ec6b06001c6f58d028e7faec127002e7919f7f adds only PR #246's metadata/favicon/logo/social assets to the proven production source. The inherited 33-file / 264-test suite, TypeScript, Vite, current 17-raster brand audit, and diff hygiene passed; JS/CSS hashes remained unchanged.
  • Cloudflare version 52b0854d-f81c-4b85-aee8-5af39f7c1ec4, deployment bb4b0d6d-009f-4e7a-9c5d-7da5b6d31e66, is live. The Worker script etag remains exact c2b631e9d99c0c986d2eb2981d9ae6e76ca81a2013832413ecef6428d6db13de; D1/Durable Object bindings, cron, and all four secret names are preserved.
  • Hosted ordinary/Facebook/Twitter HTML is byte-identical and exposes the ordered 1200x630 plus 1200x1200 images. Every social/logo/favicon hash matches source; MIME/dimensions pass; /api/v1/health is 200; the existing JS/CSS hashes remain 2770c9f4…671e / 35857dc8…cdb. Zak received the cache-busted app, card, square, and favicon URLs plus the full-v60 migration boundary.

Next up: rehearse and apply the 12 production migrations under the production controller before promoting the complete merged v60 runtime. This static release does not claim that promotion.

2026-07-18 — PR #246 digital-brand merge receipt (docs-only)

  • Ready PR #246 final head 36bada001959ab53cd04e2e6e573c03ddc03afb5 passed hosted GitHub CI and merged to main as fb3feeb078f18dcf6dfc68ad0445d5c99a6e9c8d. Zak (killerabbasi) was requested as reviewer and separately texted the exact merge, no-copy-delta, and QA status at +17739974600.
  • This closeout reconciles the current roadmap, readiness packet, copy ledger, and implementation note/index to merged-source truth. It changes no app source, public copy, provider state, or deployed asset.

Next up: an authorized production deployment must separately prove served MIME/dimensions/hash, favicon cache refresh, and third-party social previews; no provider or deployment action occurred in this docs-only closeout.

2026-07-18 — Supplied Soldi digital brand pack (source correction; not deployed)

  • Reconciled ~/Downloads/soldi-brand-assets/ against exact origin/main 5d1a755814ba58e1cfcaa249cd4d655647ed488f. The supplied transparent logo is already the immutable checked-in source byte-for-byte (30adbc8f…), so the real app logo remains unchanged rather than being redrawn.
  • Promoted the supplied circular S (104c107f…) to the small-format identity authority and regenerated opaque 16/32/48/180/192/512, maskable, three-frame ICO, Apple-touch, and conventional root fallback outputs. Versioned icon discovery is deliberate because browser favicon caches survive same-path deploys.
  • Recreated the supplied thumbnail direction as exact opaque 1200x630 and 1200x1200 outputs using the current v60 Open Market capture. The sheet's stale The PPL Marketplace, Probate, and trust-badge copy did not ship; the established Exclusive Seller Lead Marketplace descriptor remains the only discovery copy. The full no-copy-change disclosure is appended to docs/plans/soldi-brand-assets-copy-ledger-20260716.md.
  • Extended the deterministic audit to bind all three supplied source hashes, 17 raster dimensions/alpha contracts, favicon aliases/ICO frames, manifest, ordered Open Graph images, absolute Twitter metadata, Worker asset configuration, and built copies. bun run verify now runs that audit automatically. The first GitHub run passed 726 tests/build but exposed a runner-portability defect (identify absent); the corrected required audit reads PNG/ICO headers in pure Node, while ImageMagick remains local-generation-only. Generated PNG metadata is stripped and consecutive fixed-input renders are byte-identical.

Next up: exact-head review and one ready PR with Zak requested. After merge, an authorized production deployment must separately prove served MIME/dimensions/hash, favicon cache refresh, and third-party social previews; no provider or deployment action occurred in this source session.

2026-07-17 — Protected staging, real Stripe funding, and hosted v60 acceptance

  • Corrected and provider-proved the camolechowski@gmail.com Cloudflare token against the exact Soldi account, Workers, D1, zones, routes, and custom domain. Deployed the exact PR #196 train repeatedly through the fail-closed controller; the final pre-ledger receipt was 572a3c2b1543e39726837e45cd9fdae6ae8faca0, deployment 5f15e35f-d66e-4ac4-8712-b29fb12e9675, Worker version 92cd0c4d-34f8-42b1-a734-05b08c205591, and app-assets digest 019480da8baa1bef274e0c730553a894c807abf8a2db557aff992a70add9df12.
  • Repaired Wrangler JSON-prefix/readback compatibility and moved remote seed mutations to Cloudflare D1's transactional batch endpoint. A hostile staging sentinel proved rollback. The receipt-bound fixture is idempotent at nine marked leads, three ranked Territories, 12 available leads (4 Cold / 4 Warm / 4 Hot), zero collisions/legacy/economic references, and unchanged purchase/refund/portfolio counts.
  • Completed a real $1,000 Stripe sandbox Checkout and webhook. The demo wallet moved from $5,510 to $6,510; Transactions shows the typed Stripe funding row and running balance; the wallet ledger count moved from 9 to 10 exactly once.
  • Hosted QA covered the six v60 screens at desktop and exact emulated 390x844: correct headings, 390/390 width, no forbidden old-app copy, no failed requests, and no console errors. QA found and corrected Territory rank display; active rows now show Position #1/#2/#3, while null/paused rows retain Position unavailable. Focused proof passed 2 files / 14 tests; full proof passed 79 files / 726 tests, TypeScript, Vite, docs build, JSON, and diff hygiene.
  • Replaced the canonical artifact's self-staling docs-head literal with a durable authority rule: immutable runtime-bearing e97cfd3 plus assets digest are tracked in source; the exact final PR head must equal app health, Stripe health, and the private provider receipt and is recorded on PR #196 after the last deploy.
  • Deployed FHC exact merged main 6615f94 as Worker version ec6c985b-44c6-412b-bb8e-174c839db198; 966 pages built, sampled English/Spanish routes returned 200, and the challenged fabricated-voice phrases were absent from live Chicago/Miami/South Side HTML. Deployed Elite Flippers exact merged 0d898d0 as Worker version 86cb3b77-ae54-4c6f-8868-1c97c9ba4220; apex/www returned 200, live HTML was byte-identical to the prerender, and every requested numeric/risk claim was absent.

Next up: deploy this final self-resolving ledger head, record the immutable receipt on PR #196, finish Terra/high exact-head review and physical-iPhone confirmation, then run the separately gated retained-production rehearsal before any production promotion.

2026-07-17 — FHC #236 merged and reconciled into the v60 launch train

  • Final-reviewed Zak's FHC PR #236 exact head f6647d2958fb8c8bc5cedc68ef03b4120b597f14: 966 pages / 255 Spanish twins, FHC audit 0 blockers, FHC 547/547, targeted guard 67/67, root app 354/354, clean diff/worktree. Corrected only the live PR-body scope/count wording; no additional product-copy edit was made. PR #236 merged to main as 6615f94d51757f9afee12f5857e3249e43cf14ae.
  • Reconciled that exact main advance into PR #196's exact 4fe5959 train by normal two-parent merge 7c0e4e6ce48bb4e80cdc44c3b92e908b12cc87f8; no conflicts, squashes, rebases, or dropped Zak history. Integrated proof passed root 79 files / 725 tests, FHC 547/547, FHC build/audit, staging dry-run, and diff hygiene.
  • Exact deploy payloads are prepared for FHC 6615f94, Elite 0d898d0, and the reconciled Soldi staging train. No provider upload occurred: the named 1Password item still returned the rejected Cloudflare token (code 1000), and the only connected Chrome extension profile was the unrelated flowsystems.live account.

Next up: replace/verify the exact-account credential, push the train reconciliation, deploy and publicly verify Elite + FHC, then deploy the exact Soldi train to protected staging with its provider receipt and complete hosted acceptance. Soldi production remains HOLD behind retained-data rehearsal and promotion gates.

2026-07-16 — PR #245 operator-authority wording P2 correction (docs-only)

  • Independent rereview found no code defect in fixed-zone head 2a54e84; it found an overbroad documentation implication. Workers Scripts Edit + Workers Routes Edit is only the fixed-zone read-only preflight scope, not the full staging operator token or authority set. Zone Read remains absent; fixed detail remains GET /zones/22dfb4f39d708e227c63dbc9d344e955 with exact id/name/account validation.
  • Camo is the authorized Cloudflare and Stripe provider operator. The full staging operator sequence still separately requires repository-mandated DNS Edit/custom-domain authority for domain operations and scoped D1 Edit for Time Travel bookmarks, remote migrations, and staging data actions. Neither is implied by a passing preflight; actual execution waits for scoped-token verification and an explicit receipt-bearing run.
  • No code behavior changed. Documentation/JSON/hygiene and existing focused/full gates were rerun; no Cloudflare, D1, Stripe, browser, provider, deploy, or external message action occurred.

Next up: independent exact-head review. A future authorized operator must satisfy the separately scoped authority requirements and mint a complete provider receipt; ff75918 remains uploaded-without-receipt and unaccepted.

2026-07-16 — PR #245 fixed-zone authority P2 correction (source-only handoff)

  • Independent review correctly held exact PR #245 head 9699268e1c21b463d2a0b759df617c19de1795d8: the first fail-before-upload preflight used GET /zones?name=soldi.cc, which would require Zone Read and exceeded the prescribed deploy-token authority. The deploy token remains limited to Workers Scripts Edit + Workers Routes Edit; Zone Read is not added.
  • The preflight now reads only fixed known zone detail GET /zones/22dfb4f39d708e227c63dbc9d344e955, then requires that returned id, name: soldi.cc, and account.id: 2fb55b3d56fa4a0cb926515ecd0b1a6f are exact before it reads that same fixed zone's Workers Routes endpoint or accepts the staging.soldi.cc / soldi-staging custom-domain attachment. This reverses the earlier name-resolution decision append-only; it removes the unnecessary scope while strengthening target identity.
  • Fake-only coverage rejects wrong fixed zone id/name/account, malformed zone envelope, and fixed-zone HTTP/auth failure along with the existing code-10000 routes, missing-token, malformed-routes, and wrong-domain failures. Frozen focused proof passed bun run test:staging 34 tests / 121 expectations and bun run test:production-control 17 tests / 62 expectations. Full root/docs/hygiene proof is recorded with the exact follow-up head; no Cloudflare, D1, Stripe, browser, provider, route, bookmark, seed, deployment, or production call occurred.

Next up: exact-head review of the narrowed token contract. Any future authorized staging retry still must pass the fixed-zone read-only preflight and mint a complete provider receipt; the existing ff75918 upload remains unaccepted.

2026-07-16 — Staging authority fail-before-upload repair (source-only handoff)

  • The clean exact candidate ff75918b5f1f336c65d2d7c3648be6765ee7fcc0 encountered a real staging authority failure: Wrangler uploaded and activated Cloudflare version cf78dc65-c0b7-4022-a7a6-676344efad47, then its required zone Workers Routes read failed with API code 10000 under --domain staging.soldi.cc. No deployment receipt was minted. Public health reported exact ff75918; served Stripe identity was test account acct_1TtjDjPuLV917S5K; served social-card source hash, manifest, and meta matched source. Those facts prove only an uploaded-but-unaccepted hosted version, not deploy acceptance.
  • tools/staging/authority-preflight.mjs now performs a fixed-target read-only Cloudflare preflight before the exact-Git snapshot, frozen install/build, temporary config write, or Wrangler executor. It requires a non-empty token, exact account 2fb55b3d56fa4a0cb926515ecd0b1a6f, one soldi.cc zone bound to that account, a successful read of that exact zone's Workers Routes endpoint, and one staging.soldi.cc custom-domain object attached to soldi-staging and the resolved zone. HTTP/auth failure, malformed envelope, missing/ambiguous/wrong account/zone/domain/service, or missing token stops before an upload; no preflight endpoint writes or persists a token/value.
  • Fake-only adversarial coverage reproduces the routes API 10000 failure and proves no snapshot/executor upload follows. It also rejects absent token, ambiguous/wrong zone, malformed routes envelope, and wrong domain service; the healthy deployment fixture proves all four authority reads precede snapshot creation and Wrangler deploy. bun run test:staging passed 31 tests / 117 expectations; bun run test:production-control passed 17 tests / 62 expectations; root verification passed 79 files / 725 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index. JSON, diff, conflict, and clean-worktree gates remain recorded with this handoff.

Next up: independent exact-head review and an explicitly authorized protected-staging retry with a token that passes the new read-only authority gate. A seed run, final browser evidence, physical iPhone evidence, provider receipt, hosted acceptance, and every production action remain open; no provider call was made in this repair lane.

2026-07-16 — PR #243 D1 invariant-envelope P2 repair (source-only handoff)

  • Independent Terra/high rereview held exact head 78b198f because the old invariant parser accepted the syntactically valid empty-results envelope and emitted [0,0,0,0] assertions. The defect was reproduced locally with the fake-only rehearsal executor before repair; no provider operation was used.
  • Replaced recursive result discovery with one strict documented D1 execute envelope: success:true, finite non-negative meta.duration, exactly one result set, empty foreign-key rows, and exact scalar {count:0} rows for wallet, NULL property_identity_key, and duplicate-key checks. The duplicate query now wraps GROUP BY/HAVING in an outer count, so healthy zero duplicates proves one scalar row. Applied migration readback now queries the fixed d1_migrations table and requires the complete ordered {name,status:"applied"} inventory; filename containment and unsupported migrations list --json are gone.
  • Fake-only regressions reject reviewer-empty, missing, duplicate, multirow, wrong-alias/type/status, nested-result, positive-count, success:false, and malformed-metadata envelopes while retaining fixed-account cleanup, GitHub approval, and structured Time Travel coverage. Frozen install was unchanged; production control passed 17 tests / 62 expectations; staging controller/demo-seed 24 tests / 105 expectations; root verification 79 files / 725 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; JSON, diff, and conflict scans passed.

Next up: push the exact repair head, refresh the PR provenance, and stop for a new exact-head Terra/high rereview. No rehearsal, provider, Cloudflare, D1, Stripe, bookmark, export, deploy, merge, or external message is authorized.

2026-07-16 — PR #243 exact d80 train integration (source-only handoff)

  • Normally merged exact reviewed train d80f2e0a3438b152c62193b1911c99c53d64d434 into prior PR #243 head 151e49fa9eb7d0d55cb525a608e4988cff86e08a as 93b638c889a0c2535d69198ba24fcec2081e0fb6. Parents are preserved in that order; conflicts were restricted to shared append-only release documents and resolved as an additive union.
  • The train retains reviewed Hosted-QA/funding and canonical-brand source together with prior Package, seed, and production-control histories. tools/production/** is byte-identical to 151e49f; no production-controller semantics changed. Frozen install was unchanged; production control passed 14 tests / 36 expectations; staging control/demo-seed 24 tests / 105 expectations; root verification 79 files / 725 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; JSON, diff, and conflict scans passed. No deployment, rehearsal, provider, Cloudflare, D1, Stripe, bookmark, migration, cleanup, or external message occurred.

Next up: push the exact head, refresh PR provenance, then stop for independent exact-head review.

2026-07-16 — PR #243 hardened production-control integrated handoff (source-only)

  • Integrated the exact requested launch train cfbc5cd713c8d402e1017ecea51a55fe86e16f9d as merge b9b8f95e9ff4e5128221e373d8beef23be9ae5da, retaining its Package identity protection and staging demo-seed code/docs while preserving the production-only controller policy.
  • Repaired every Terra HOLD seam: immutable external GitHub APPROVED production-go review authority with strict SHA/config/diff binding and a maximum 24-hour submitted-to-expiry window; private fixed-account D1 config on create/info/delete; immediate cleanup-target assignment after create; local-export erasure plus escalation even on remote delete failure; zero-NULL/duplicate property identity checks; and exact structured temporary-only Time Travel restore/post-restore proof.
  • Source-only verification after the merge: frozen install unchanged; production controller 14 tests / 36 expectations; staging controller/demo-seed 24 tests / 105 expectations; root bun run verify 77 files / 711 tests, TypeScript, and Vite; docs build 10 internal + 2 client docs + index; JSON parse and git diff --check passed. No Cloudflare, D1, Stripe, bookmark, export, migration, restore, deploy, remote cleanup, or token operation occurred.

Next up: push the final integrated head and stop at independent exact-head review. Private retained-data rehearsal, fresh production bookmark, hosted acceptance, and promotion remain separately authorized future work.

2026-07-16 — Production-control and retained-data preflight lane (source-only)

  • Added a production-specific tools/production/ controller rather than extending staging policy. It permits only canonical checked-in Worker soldi, app.soldi.cc, production D1 soldi, canonical cron/workers.dev/binding intent, and a clean exact full SHA. It path-fences private plan/receipt artifacts, recomputes current config/assets/migrations, renders a redacted config diff, and requires an externally fetched, exact-commit GitHub APPROVED production-go review from immutable Zak user id 236636852 / killerabbasi in camolechowski/soldi; a local deploy operator cannot mint authority with JSON/token text.
  • The retained-data rehearsal deliberately uses the safe D1 model: private wrangler d1 export soldi --remote, then fixed-account config-fenced temporary D1 creation/info confirmation before import, complete migration/invariant/readback proof (including zero NULL/duplicate property keys), and structured Time Travel restore plus post-restore readback only on that temporary target. Nested cleanup erases raw local export even if remote delete fails, emits an escalation, and fails closed. It requires acknowledgement that export blocks database requests, does not claim D1 clone/fork support, and contains no production source restore path.
  • The eventual upload takes a frozen exact Git snapshot, rebuilds, compares snapshot/current-worktree digests, and requires post-upload authority for exact Worker version/deployment, complete bindings/plain-text vars, secret names, custom domain, zero routes, workers.dev, and cron. Rehearsal, bookmark, upload, provider, migration, export, cleanup, Stripe, and deployment operations were not executed in this source lane.
  • Local repair proof includes untrusted GitHub reviewer/repository/binding, future/unbounded/expired attestation, wrong account, create-then-info failure cleanup, delete failure/raw-export erasure, null property key, structured rollback, post-restore drift, and provider drift regressions. Final integrated verification is recorded only after the required exact train merge. The production runbook is docs/runbooks/v60-production-control.md; it cites current Cloudflare Time Travel and import/export limits.

Next up: independent review of this source-only control lane; only after review and explicit owner/operator approvals may the private real-data rehearsal and the separately gated hosted-acceptance sequence be scheduled.

2026-07-16 — Exact PR #242 train merge into canonical-brand branch (local; review handoff pending)

  • Fetched and verified origin/orchestrator/marketplace-v60-20260713/merge exactly at 94757fbe1622d7b91458f8200a936595622c5eb4, then normally merged it into the PR #244 brand branch as 67d98eac09903df2818a59cbf8cda05ba2ebc053. Conflict resolution preserves both PR #242 hosted-QA/funding source/readiness records and canonical-brand copy/audit records append-only.
  • Every checked public brand artifact and direct mark-rendering source is unchanged from 9a9e69b: app/public/brand/**, favicon, manifest, Logo, TopNav, and Login. The sole overlapping consumer-file delta is PR #242's independent Layout support-clearance import/style and its test; its Logo JSX/source/alt/dimensions are unchanged. No logo asset, metadata, or generator behavior was modified.
  • Frozen install, focused 3 files / 4 tests, and root bun run verify 79 files / 725 tests with TypeScript and Vite passed. Docs build 10 internal + 2 client docs + index, the deterministic brand audit, exact brand-identity diff, manifest JSON, conflict-marker/diff checks, and public .DS_Store scan passed. No deploy, provider mutation, migration, or PR merge occurred.

2026-07-16 — Canonical Soldi brand assets (local source; independent review pending)

  • Added immutable app/public/brand/soldi-logo.png, whose audit-enforced byte SHA-256 is 30adbc8f75f5bf1377c3f7b1714be1ae505a9d43dc3b9113ff92c805f31bd630 (separate ImageMagick pixel signature 9a8c70fae8d1dafb86ca91cb3b181767cf76c05237db0d8e18c16030a42f1dad). The supplied 1536x1024 RGBA source was copied byte-identically and is never redrawn, recolored, or recompressed.
  • Replaced real app company-mark treatments in the shared desktop/mobile navigation, Login, support panel, and footer with one accessible Logo component. The app retained existing v60 geometry/tokens and motion behavior; source tests plus local 1440px and emulated 390px browser inspection found no horizontal overflow or logo distortion.
  • Added derived alpha-preserving mark/dot assets, opaque 1200x630 discovery card, favicon/Apple/PWA/maskable icon set, manifest, complete route-agnostic canonical/Open Graph/Twitter/JSON-LD metadata, and a deterministic audit that also checks the app/dist Cloudflare ASSETS source configuration and built copies. The exact old-to-new public-copy ledger for Zak is docs/plans/soldi-brand-assets-copy-ledger-20260716.md; it introduces no price, Package, auction, testimonial, or Fair Home Cash claim.
  • Regeneration deliberately requires SOLDI_BRAND_FONT instead of hardcoding macOS Verdana. The checked-in rendered assets are cross-platform deploy artifacts, but regeneration is only deterministic for a caller-supplied exact font binary; it is not claimed cross-platform. No deploy, host/cache-header claim, FHC, or preview change occurred.
  • After the brand commit, normal merge fa53e0c integrated exact train cfbc5cd713c8d402e1017ecea51a55fe86e16f9d, retaining the Package owner-bound readiness, staging reseed, runbook, deck, and append-only documentation changes. The Soldi home link now has its own flex min-h-11 min-w-11 target around the unchanged 40px image; fresh local browser measurements were 70.95×44px at both 1440px and 390px, with mobile scrollWidth=390.
  • Final local proof on the merged target-corrected head passed frozen install, the focused 3-file/4-test brand/layout suite, root bun run verify 78 files / 712 tests with TypeScript and Vite, docs build 10 internal + 2 client docs + index, the deterministic brand audit, manifest JSON, diff/conflict checks, and no app/public/.DS_Store. Local Vite preview returned image/png for the card and application/manifest+json for the manifest; it is source/browser evidence, not a hosted cache-header claim. Independent review is next; no deploy occurred.

2026-07-16 — PR #242 additive exact-train integration (local; independent rereview pending)

  • Additively merged exact origin/orchestrator/marketplace-v60-20260713/merge head cfbc5cd713c8d402e1017ecea51a55fe86e16f9d into PR #242 as two-parent commit f477c67b9f6a1c1c79aeda2c1c03e67ac3847e0c, retaining its approved Package readiness/copy and staging demo-seed code/documentation. Conflict resolution was limited to shared append-only release records; inherited app/src/pages/Market.tsx and app/src/pages/Market.test.tsx were not modified by PR #242.
  • Train-relative source fence passed: git diff --name-only cfbc5cd...HEAD contains the PR #242 mobile/payment/security/doc delta only; explicit git diff --exit-code for both Market files passed and no Package or seed source path appeared.
  • Combined focused proof passed 7 app files / 79 tests plus TypeScript; inherited staging controller/demo-seed proof passed 24 tests / 105 expectations. Root bun run verify passed 78 files / 724 tests with TypeScript and Vite; docs rebuilt 10 internal + 2 client docs + index; git diff --check passed. No deployment, provider, D1, or merge to the base train occurred.

2026-07-16 — PR #242 Terra fixture/cache hardening (local; independent rereview pending)

  • Exact Terra review held PR #242 head 4beb007 for two source-contract defects: omitted APP_ENVIRONMENT plus a loopback request URL could mint local fixture funds, and authenticated funding-capability responses carried no cache boundary. The original mobile support geometry and configured-Stripe direct Checkout corrections remain intact.
  • Centralized trusted local-fixture authority in isTrustedLocalFixtureEnvironment: only literal APP_ENVIRONMENT=development or test qualifies. Payment capability and fixture deposit use that environment-only predicate and do not inspect request URL or Host. Undefined, unknown, staging, and production report capability unavailable and each deposit attempt returns 503 stripe_not_configured with no D1 batch.
  • Funding capability now sends Cache-Control: no-store and Vary: Cookie for authenticated 200, unauthenticated 401, and wallet-schema-not-ready 503 responses. Vary: Cookie is retained defensively even with no-store because authentication changes the valid response boundary.
  • Focused proof passed 4 files / 50 tests plus TypeScript: explicit development/test fixture success, four non-trusted environment capability/deposit regressions across loopback URLs, configured Stripe, and cache headers on 200/401/schema-503. Root bun run verify passed 78 files / 715 tests with TypeScript and Vite; bun run build:docs rebuilt 10 internal + 2 client docs + index; git diff --check passed. Source repair commit 99fadee02af9b5df635b2177a3f4f699a018a77d was pushed, and PR #242's body was refreshed with exact provenance and test evidence; independent rereview remains next. No deployment, provider, D1, or merge occurred.

2026-07-16 — Hosted-QA P1/P2 source repair (local; independent review pending)

  • Worked from exact hosted-QA source 4578d7ba10a08135cd10bd6fc97dd04c45e2c6c7 in isolated branch orchestrator/soldi-final-wave/hosted-qa-fixes. The staging receipt proved two source defects only: at effective 500px CSS width the fixed support control covered the Territory + Add More Territories action, and normal Add funds first produced a same-origin /payments/deposit 409 before starting Stripe Checkout.
  • Mobile support now shares a single 44px fixed-action contract with the Territory button: the launcher and open support panel sit above the bottom primary action by 16px at the mobile breakpoint, including the safe-area inset. Desktop coordinates and v60 visual tokens remain untouched. A pure geometry regression proves non-overlap at both the observed 500x844 and required 390x844 CSS widths; layout tests pin the rendered CSS contract.
  • Added authenticated GET /payments/funding-capability. It returns stripe when the configured provider route is available, local_fixture only for an unconfigured localhost development request, and unavailable for unconfigured hosted requests. Billing now starts the existing idempotent /wallet/checkout route directly for Stripe and uses /payments/deposit only for an explicitly confirmed local fixture; wallet crediting remains webhook/ledger owned. No Stripe, Cloudflare, D1, or deployment operation occurred.
  • Focused source proof passed 5 files / 30 tests, including configured-Stripe direct Checkout and unconfigured local-fixture paths. Final root verification passed 78 files / 708 tests with TypeScript and Vite; docs built 10 internal + 2 client docs + index; git diff --check passed. Commit/push and non-draft reviewer handoff remain next. Protected-staging true-390 pointer and zero-failed-request evidence must be rerun after an independently reviewed deployment; this local record does not claim it.

2026-07-16 — PR #241 Terra P3 runbook contract correction (source-only)

  • Final Terra rereview held one documentation P3: the hosted-gate runbook still said revalidation config must be byte-identical to the receipt. Corrected it to the implemented contract: derive the checkout root from main, validate with renderStagingConfig(input, derivedRoot), canonicalize only local source paths, compare canonical text/digest before provider calls, and keep all non-path semantics exact. No runtime, migration, fixture, or hosted boundary changed.
  • bun run verify passed 77 files / 702 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; git diff --check passed. Exact-head PR-body provenance refresh, push, and a new independent-review handoff follow. No Cloudflare, Stripe, remote D1, deployment, migration, Time Travel, or hosted command is authorized or executed.

2026-07-16 — PR #241 Terra hostile-reseed repair (source-only; exact-head review pending)

  • Terra/high held PR #241 at 540183426887b38d38e812cc904f9093730d2b82: receipt revalidation incorrectly compared checkout-specific absolute config paths, the reseed trusted the receipt-provided asset digest, a post-preflight collision could commit a partial fixture set, cleanup could not recover that partial set, and the PR body named the runtime parent rather than the PR head. No hosted command was run while repairing those findings.
  • The staging deployment receipt now stores a canonical semantic configuration, normalizing only local source paths. The reseed command rebuilds the exact Git candidate with frozen install/build and independently compares its asset digest before provider or D1 access. A direct second-clean-worktree regression proves a controller-style receipt reaches only mocked provider/D1 dry-run readback; a substituted digest fails before either call.
  • Apply and cleanup now use BEGIN IMMEDIATE post-lock guards. Conditional plain inserts prevent all fixture writes when a lead collision, competing Territory, context drift, or economic reference appears after preflight; the command then fails through its readback contract. Conditional marker-bound cleanup preserves ledger truth, blocks a post-preflight economic reference, and safely removes an old partial marked set without deleting an unmarked colliding row.
  • Focused bun run test:staging passed 24 tests / 105 expectations against fresh 00010036 migrations, including three two-connection hostile races, cleanup race/recovery, canonical cross-worktree receipt revalidation, and asset-digest early refusal. Frozen install made no changes; bun run verify passed 77 files / 702 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; git diff --check passed. Exact-head review handoff remains required before a new PR review; no Cloudflare, Stripe, remote D1, deployment, migration, Time Travel, or hosted dry-run/apply/cleanup occurred.

2026-07-16 — Receipt-bound staging demo-data reseed (source-only)

  • Added bun run staging:demo-seed as the only checked-in staging demo-data operator path. It requires the exact private deployment receipt for the same clean full SHA and live-revalidates the receipt's Worker version, full binding topology/plain-text values, secret names, zero cron, disabled workers.dev/previews, and staging.soldi.cc before it can form a remote D1 command. The target is fixed to soldi-staging / isolated D1 516586fe-4d84-4f41-a27a-96bf9d0697c2; production worker/host/D1 names and ids fail closed.
  • The deterministic marker-owned fixture adds nine reserved-fictional Investor leads: exactly three each Cold/Warm/Hot and all four current situations. Together with the canonical three v60 leads it requires a 10–12 available-lead Market. Three marker-owned U_DEMO_V60 Essex/NJ pre-foreclosure Territories exercise rank positions 1/2/3 and $250 top-bid context. No new migration, old taxonomy, gamer payload, production fixture, or target override was introduced.
  • dry-run is readback-only. apply and cleanup require literal confirmation; complete fixture reruns do not write, partial/colliding state fails, and cleanup deletes only exact marker-bound IDs. Wallet transaction, Market purchase, refund request/outcome, and portfolio snapshots must be unchanged; any fixture economic reference blocks cleanup instead of deleting history.
  • Local proof passed bun run test:staging (17 tests / 73 expectations) with real fresh migrations 00010036 for fixture idempotency, exact tier/situation count, reserved-contact/current-taxonomy checks, Territory positions/top bid, production/non-staging refusal, ledger preservation, and cleanup scope. Full bun run verify passed 77 files / 702 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; JSON parse and git diff --check passed. No deployment receipt was created or read, no Cloudflare/Stripe/D1 call occurred, and no hosted staging apply/cleanup was attempted.
  • Next: after an explicit staging execution authorization, create a fresh Time Travel bookmark, deploy the exact committed head through the existing controller, run the receipt-bound dry-run/readback, and only then consider the separately-confirmed apply. Hosted execution remains outside this source PR.

2026-07-16 — Exact staging control and Stripe mode fence (pre-deployment)

  • Created codex/staging-control-4219195 from exact launch train 421919505086994a19bbff71a9f4c805845e21c9. The standalone controller accepts only soldi-staging, staging.soldi.cc, isolated D1 516586fe-4d84-4f41-a27a-96bf9d0697c2, test-mode Stripe, auctions off, cron off, Package scheduler absent, workers.dev/previews off, and a clean full Git SHA. It builds an exact private Git snapshot and provider-reads the unique Worker version/deployment, secret names, domain, subdomain, and schedule state.
  • Added staging health provenance using Cloudflare version metadata and a staging-only sanitized Stripe /v1/account identity surface. Added a defense-in-depth Stripe provider-mode guard: staging plus test accepts only sk_test_; production plus live accepts only sk_live_. A mismatch fails before funding-intent persistence and inside the shared provider request helper, covering Customer, Checkout, and Portal.
  • Terra/high's first exact-head review correctly held the child: mutable Stripe metadata was not identity authority, operational deploy/readback used the worktree Wrangler instead of the frozen snapshot, and the deploy function had no fixed receipt-producing command. The repair binds staging to immutable Stripe account acct_1TtjDjPuLV917S5K, rejects a provider key when environment/mode is unbound, adds no-store to staging provenance health, uses and hashes the snapshot Wrangler for upload and immediate provider readback, and adds override-free bun run staging:deploy with a private full receipt.
  • Provider preparation touched staging only: removed its inherited one-minute cron and attached staging.soldi.cc as custom-domain id 166ab9a82dc54d854123fb840fc6e3a1ace30de4. Read-only staging D1 preflight found migrations through 0031, no malformed/Agent profiles, invalid wallet rows, duplicate non-null property keys, or Package state/cycles. Production Worker and D1 were untouched.
  • In Stripe's Soldi sandbox, active webhook destination we_1TtjFvPuLV917S5KUEdwTcNV now targets canonical https://staging.soldi.cc/api/v1/webhooks/stripe instead of the former workers.dev review URL. No buyer-visible copy or production Stripe resource changed.
  • After PR #233 merged as train 6916b0f, staging Time Travel bookmark 00000006-00000000-000050ab-7ddf723e2eab88f63ddc2d6bdc85b1a5 was recorded and remote migrations 00320036 applied cleanly to isolated D1 516586fe-...; nothing remains pending, wallet/property/foreign-key checks are clean, and available Agent plus legacy-distress rows are zero. The first exact deploy failed closed before upload because strict Wrangler saw the provider-managed domain and public workers.dev/previews as dashboard drift. The signed-in Cloudflare UI then disabled workers.dev and previews; this follow-up repeats fixed --domain staging.soldi.cc on the strict deploy command so the existing required domain is explicit rather than contradictory.
  • PR #234 merged as train c9ae348, but its retry also stopped before upload: Wrangler --strict rejects the expected new full-SHA/account-id variables themselves, so no genuine release can pass it. The bounded correction removes only --strict. Terra/high then held #235 because Wrangler could delete unconfigured dashboard variables before the receipt inspected them; later probes found preserved JSON, partial-topology bypasses, and a provider-only forged live-revalidation path. The repair adds fixed --keep-vars, requires the exact uploaded version's complete binding name/type topology plus all plain-text values to equal the rendered allowlist, and validates the complete receipt plus byte-identical config before any later provider revalidation. Preserved JSON, unknown types, malformed entries, duplicates, collisions, and forged receipt/config substitutions now prevent authority. Fixed domain/config/snapshot/toolchain inputs and unique version/deployment, secret-name, zero-cron, disabled workers.dev/preview, and exact custom-domain readback remain.
  • Post-repair proof passed: Stripe/provenance/identity focused Vitest 39 tests; staging controller 12 tests / 46 expectations; full app 77 files / 696 tests, TypeScript, and Vite; docs build 10 internal + 2 client docs + index; fresh local migrations 0001–0036. The staging D1 is already migrated through 0036; pending gates are exact child rereview/merge, exact Worker deployment/readback, Access policy, served Stripe identity plus Checkout/webhook, desktop/mobile hosted QA, and only then production consideration.
  • Terra/high approved exact #235 head 8fb0da6 with zero P0–P3 findings; it merged as train 6961cd0. A narrowly scoped Workers Scripts/Workers Routes token then produced deployment 5db67132-5025-4455-807d-472677bfcc1a and Worker version 7af1e587-af64-429d-9474-222089debe6b; no-store health serves exact SHA 6961cd0 at staging.soldi.cc. Stripe key/account-id readback is correct, but the unactivated sandbox stores its provider-owned name in settings.dashboard.display_name while business_profile.name is null. A bounded fail-closed fallback child is in verification; Checkout/webhook and hosted browser acceptance remain open, and production remains untouched.
  • Terra/high held the first fallback head on three P2 edge cases despite green tests: empty primary names suppressed fallback, whitespace-only names were accepted, and documented-null settings rejected a valid primary name. The correction trims both candidates, treats blank as absent, accepts nullable settings, and pins all three failures; no deployment or merge occurred at the held head.
  • The corrected #238 head passed fresh Terra/high with zero P0–P3 findings, merged as 91b51c5, and deployed as Worker version cc341282-8506-4a3d-88ca-31f806ec52cc. General health proved that exact SHA, while Stripe health stayed 503. Stripe request logs showed the Worker used the correct test key and received GET /v1/account 200; direct shape readback proved the standalone sandbox omits business_profile entirely. A one-field optional-schema follow-up with an exact omitted-field regression is now required before the next deploy; production remains untouched.

2026-07-16 — v60 Package identity-bound readiness correction (local; final rereview pending)

  • Final Terra/high rereview held exact PR #240 head b1f1b14 on one P2 only: a resolved U1 ready status had no owner, so React's anonymous/U2 pre-effect render could expose ready-only Package copy before cleanup. The correction stores { userId, status } and derives readiness only for a current authenticated matching owner plus literal fulfillmentReady=true; existing AbortController cleanup remains the transport fence.
  • New Market regressions directly prove U1-ready cache fails closed for anonymous and U2 before effects, exercise U1-ready -> anonymous and U1-ready -> U2 pending UI transitions, and hold a late U1 completion until U2 resolves. Every hero, recommendation/action, Hot-modal, and unlocked-lead delivery/action literal remains absent until the U2-owned ready response arrives.
  • Required make-it-sexy and make-it-simpler reviews were completed directly in this pane under Cam's no-normal-subagent rule. The established v60 visual treatment required no cosmetic change; the cache remains a single-consumer local state seam with no shared extraction warranted. Frozen install; the reviewer-aligned 100 tests / 8 files; full bun run verify 77 files / 711 tests, TypeScript, and Vite; docs build 10 internal + 2 client docs + index; and git diff --check passed. PR/report refresh, exact-head commit/push, and final rereview remain next. No deploy, merge, Cloudflare, Stripe, or D1 mutation occurred.

2026-07-16 — v60 Package copy and qualityScore P2 correction (local; superseded review head)

  • Independent review of PR #240 exact head 219396b held four P2 defects: the successful direct-purchase dialog bypassed readiness, same-user server revocation could leave ready copy cached, the two retained Admin qualityScore contracts had no server field, and the new mobile Package link lacked a 44px target.
  • Market.tsx now passes literal readiness into the unlocked-lead dialog, so its automatic-delivery claim and See the package action render only while fulfillmentReady===true. Package status is cleared synchronously after purchase and on visible-window return, then re-fetched; paired focus/visibility signals coalesce into one request while the existing identity abort fence remains. False, loading, and error direct-purchase reveal regressions assert no delivery claim/action.
  • The protected /admin/leads/pending and /admin/supply-funnel SQL selections and response mappers now return l.quality_score as qualityScore; real route-response tests pin both fields. Buyer Market/auction mapper omission regressions remain unchanged. The recommendation Link has explicit min-h-11 and a focused assertion for the locked 44px mobile target.
  • Required polish was completed directly in this pane: the existing v60 refined/dark visual system, scoped banner hierarchy, reduced-motion modal path, and existing responsive layout already fit this corrective change, so make-it-sexy made no additional cosmetic edit. Direct make-it-simpler review found no reusable hook/extraction or quality cleanup; it did add immediate clear plus coalesced resume revalidation to prevent duplicate transport. A normal-agent attempt was terminated under Cam's later no-normal-subagent constraint; its output was not used.
  • Verification passed: frozen install; reviewer-aligned Market/readiness/mapper/Admin suite 95 tests / 8 files; full bun run verify 77 files / 706 tests, TypeScript, and Vite; docs build 10 internal + 2 client docs + index; and git diff --check. The built recommendation class is .min-h-11{min-height:calc(var(--spacing) * 11)} with --spacing:.25rem, a 44px target at the locked 390px width. Final PR/body/report refresh, commit/push, and a new exact-head review handoff remain next. No deploy, merge, Cloudflare, Stripe, or D1 mutation occurred.

2026-07-16 — PR #232 purchaser-role authority repair (local; merge held pending review)

  • Hostile review reproduced a real direct-Market defect in an authoritative disposable D1: manually forcing an authenticated buyer_profile.vertical to agent still returned 201 and created a purchase for a valid Investor lead. The preceding Investor-only closure had fenced lead inventory but not purchaser authority; its broader “cannot list or buy” statement is superseded by this correction.
  • Added a shared persisted-vertical gate for authenticated Market list, direct buy, and server bulk. Missing, malformed, array-shaped, and non-Investor profiles fail closed; valid retained Investor rows stay routable even if old preference data does not meet the newer profile-write schema. List returns its existing empty shape; direct/bulk return existing generic 409 lead_unavailable, preventing eligibility disclosure. Direct transactional claim and purchase predicates repeat the JSON-valid Investor requirement; 0033 batch-trigger enforcement remains intact.
  • Added direct fake-route, authoritative SQLite retained-profile, and atomic-bulk SQLite route coverage. Forced Agent direct/bulk attempts leave market purchases, batch ledger, fulfillment claims, wallet/balance counters, and selected lead availability unchanged. This change neither enables buyer bulk UI nor changes canonical Cold/Warm/Hot price behavior or the removed Hot discount copy.
  • Verification passed: frozen install; focused 4 files / 32 tests; full bun run verify 75 files / 685 tests with TypeScript and Vite; fresh local D1 migrations 0001–0036; docs build 10 internal + 2 client docs + index; FHC 480 tests / 13 files, 966 generated pages, build, and audit; and scoped changed-file/added-line secret, conflict-marker, JSON, and diff checks. Commit, push, and PR #232 body refresh are next. No deploy, remote migration, PR merge, or message occurred.

2026-07-16 — Exact c8a46c3 train merge for Investor-only closure

  • Committed the bounded Investor-only Market closure on original exact base f61a0085f04efcb2f710c18129a8c401d3b30c79 as 3c95c8d, then fetched and verified origin/orchestrator/marketplace-v60-20260713/merge exactly matched required c8a46c3d476e2c4b315b95ad587d4fe5f21cd352 before a normal merge. Shared conflicts were limited to BUILD_LOG.md, the implementation-note index, and the v60 note; resolution retained both the incoming FHC/current-main receipts and this closure append-only.
  • Post-merge proof passed: root bun run verify 75 files / 684 tests, TypeScript, and Vite; fresh local D1 migrations 0001–0036; docs build 10 internal + 2 client docs + index; FHC 480 tests / 13 files, 966 generated pages, build, and audit. Scoped added-diff/changed-file secret scanning, JSON, conflict-marker, and diff checks remain required before push. No Soldi deployment, remote migration, PR merge, or message occurred.

2026-07-16 — Investor-only Market and Hot-copy closure (local child)

  • Created clean branch codex/zak-handoff-closure-20260716 from exact train f61a0085f04efcb2f710c18129a8c401d3b30c79. Added forward-only 0036_investor_only_market.sql: it normalizes valid retained Agent profiles to Investor plus wholesaler and retires only Agent inventory that remains Market-available. No historical migration was rewritten.
  • Buyer profile writes now reject Agent. Market list uses literal vert = 'investor'; direct buy's preflight and transactional claim/purchase predicates and the server-only bulk helper independently require Investor. Retained Agent sessions, malformed legacy profiles, and future direct Agent writes cannot create a route to Agent inventory. SQLite proofs cover 0035 -> 0036 retained profile/lead conversion plus foreign-key integrity, authenticated Agent-profile rejection, list exclusion, direct-buy invalid_lead_state, and no balance/purchase mutation.
  • Removed the active Open Market Hot leads at $200, not $250 recommendation, its $200 hero/modal claims, and dead state/CSS while bulk remains disabled. The rendered copy test asserts no Hot-discount phrase and canonical direct Hot $250 price coverage remains. Removed unused client-only AuthUser.heldBalance compatibility type and its fixture residue; production source had no consumer.
  • post-change-polish.js was not run: this pane has no Workflow API runner, and its agent stages conflict with the explicit solo instruction. Both make-it-sexy and make-it-simpler instructions were read and applied manually to Market.tsx and Market.styles.ts; retained responsive/reduced-motion behavior and removal-only scope meant no cosmetic addition was warranted. Frozen install, focused 5 files / 43 tests, fresh local migrations 0001–0036, and root bun run verify 75 files / 684 tests (TypeScript and Vite) passed. Expected resilience stderr remained non-failing coverage. No deploy, remote migration, PR, merge, or message occurred.

2026-07-16 — v60 train reconciliation of FHC PR #231 production receipt (no Soldi deployment)

  • Normal merge carries exact origin/main 962abd97518c8e67c7671ab6b9f068299deae438 into the v60/payment/import/package-reserve train after its prior 100b253 reconciliation. It preserves the FHC receipt for deployed source 100b253 / Worker c5786384, the route/artifact-only boundary, and issue links: freshness is deferred under #229 to 2026-08-31; missing Workers Routes token scope is tracked by #230.
  • This merge changes no Soldi app runtime, v60 UI, migration, Stripe configuration, or deployment state. FHC is independently live; the Soldi train remains unhosted and requires protected exact-SHA staging, Stripe sandbox, retained-data/migrations, hosted desktop/mobile acceptance, Zak final review, and explicit production promotion.
  • Verification for this reconciliation: root bun install --frozen-lockfile; app/root bun run verify 75 files / 682 tests, TypeScript, and Vite; FHC 480 tests / 13 files, build/audit, provenance 103/0, offline source links 8/8; fresh local D1 migrations 00010035; docs build 10 internal + 2 client docs + index; JSON, conflict-marker, diff, and secret scans passed. The earlier nonexistent scripts/provenance-check.ts invocation is command-error non-evidence; the correct data/provenance.ts --check passed.

2026-07-16 — FHC production deployment receipt for exact 100b253 (live)

  • Production serves exact source 100b253a3cefe29fbf482244f603046cfa0a48ba on Cloudflare Worker version c5786384-4ba6-4b0b-bf14-979f30b81de4. Supplied live probes passed: apex 200; www 301 to apex; canonical /es direct 200 with self-canonical HTML; /es/ 307 to /es; and a Spanish twin 200.
  • The supplied artifact receipt proves live /es, sitemap.xml, and sitemap-es.xml SHA-256 values equal the exact local artifacts. The deployed sitemap counts are 957 full URLs and 256 Spanish URLs. This is deployed artifact and route proof, not evidence that Google discovered, crawled, or indexed every URL.
  • Pre-deploy evidence: FHC 480/480 across 13 files; audit zero blockers with 12 existing thin-page warnings; provenance 103/103 comparisons; offline links 8/8; and public-output smoke passed. No public copy, data, route membership, FHC-10, or provider configuration delta was introduced by this deployment.
  • Wrangler uploaded and deployed the Worker successfully. Its attempted custom-route rewrite then returned Cloudflare authorization code 10000 because the token lacks Workers Routes permission; issue #230 tracks that token follow-up. The existing configured apex/www routes stayed attached and the live route/artifact probes above prove the new version is serving.
  • Freshness enforcement remains deferred pre-September work under issue #229, due 2026-08-31, and is not shipped or implied by this receipt. Receipt-lane verification: docs build 10 internal + 2 client docs with all walkthrough images resolving; root bun run verify 354/354 across 37 files plus typecheck/production build; and git diff --check. No additional deployment or provider call occurred in this documentation lane; ready-PR/reviewer handoff follows without merge.
  • Committed and pushed the receipt source as 9e2aa60bc8879ea4e1245058bb52f9f1c33a0156; ready PR #231 is open against main with killerabbasi requested as reviewer. No merge occurred.

2026-07-16 — v60 train reconciliation of FHC #225/#226/#228 source truth (not deployed)

  • Normal merge brings exact main 100b253a3cefe29fbf482244f603046cfa0a48ba into the v60/payment/import/package-reserve train. It retains the train's append-only Package/UI ledger and incorporates the FHC Spanish-hub sequence: #225 adds a generated /es hub for 255 existing Spanish twins; #226 emits flat dist/es.html so /es is canonical/direct 200 in local Worker proof; #228 restores the Soldi funnel asset while retaining the FHC hub capture separately.
  • Current source truth: the canonical sitemap gains one /es route (956 → 957); this is source membership only, not hosted serving, deployment, or Google crawl/indexing proof. FHC #220/#222 link-health and #223 registry work remain source-control evidence. PR #214 is independently live on FHC; no Soldi staging or production deployment occurred here.
  • Exact #228 documentation truth is retained: docs/shots/funnel-mockup.png was restored byte-for-byte from pre-#225 main 4dc59090b3adbe78abedd20ca31283dc35e8251a (SHA-256 f47cf22117d90232f6b5a3e21882d4f2f49f6326d3282b1a0f4171dc5bb199fe), while docs/shots/fhc-es-hub-local-20260716.png (SHA-256 081b713c9865f0ae160fe8ed5d0e10a556ae157d2c775e1dcc311b3500e0e8eb) is expressly local source evidence. The former CSV gap remains fail-closed on v60/PR #196 exact 6d251c7e6aa27d327bf60952e67e1bab181a7027, with local Worker-backed proof and immutable receipts; it is source/train proof, not main, hosted, or live.
  • Current FHC source receipt for #228 is 966 generated pages, 255 Spanish twins, 1,193 files, 967 recursive HTML, audit, provenance --check 103 comparisons/0 disagreements, and offline source links 8/8. These are local build/source checks, not hosted evidence.
  • This reconciliation preserves every train-side ledger record and treats the incoming FHC historical entries as source-history evidence through parent 100b253; the current roadmap, walkthrough, and implementation-notes index now carry the reconciled source/deployment truth without retroactively changing historical receipts.

2026-07-16 — Package reserve v2 corrected owner ruling (local child)

  • Created isolated child branch codex/package-reserve-v2 from exact train 8d19f446e56f054732af99ab7c4f41a0c8ac76d0; highest prior migration was 0034, so forward-only 0035_package_reserve_v2.sql is unambiguous. It archives immutable v1 readiness/state/reservation evidence, installs package-reserve-v2 authority and v2 reservation/paid-cycle triggers, and makes v1 incapable of authorizing a new fulfillment action.
  • The scheduler, reservation projection, and live activation guard now agree: each active, max_bid_cents >= 25000 Territory contributes 6 * weekly_cap, regardless of filters; weekly_cap=0 fails closed; each active or cancel-at-period-end Package contributes 25; and PPC supply is leads created in-window regardless of market status. Territory create/update defaults to and requires finite integer cap >=1; it is deliberately one-sided, so a Territory can stop a new Package sale but reserve never blocks Territory create/raise.
  • Focused local proof currently covers cap 3 -> 18, 5 -> 30, 10 -> 60, unbounded cap, statuses, package cancellation status, PPC/market-status supply semantics, daily decision replay, one-sided exact package_reserve_not_ready rollback, route validation, v1/v2 authority separation, and the truthful Weekly lead cap UI label. Full verification, docs build, source scans, commit, and push remain; no deploy, PR, or message occurred.
  • Final local receipt: focused 5 files / 70 tests; root bun run verify 75 files / 681 tests, TypeScript, and Vite; fresh local D1 migrations 00010035; docs build 10 internal + 2 client docs + index; JSON/diff/conflict and added-secret scans passed. The current post-v2 build is initial JavaScript 422.60 kB / 133.94 kB gzip with deferred Leaflet 150.05 kB / 43.58 kB gzip, superseding the earlier current-byte receipt by one gzip byte while preserving it as dated history. No deploy, PR, or message occurred.
  • Retained-data hostile correction: the first 0035 draft had not recreated v1 fulfillment authority triggers after renaming package_fulfillment_state. The follow-up restores their original insert/update authority predicates on package_fulfillment_state_v1. A retained v1 decision/state/reservation created on 0034 and then migrated in place rejects an attacker state mutation with package_readiness_authority_required; decision and reservation mutation remain rejected by their immutable triggers. Final follow-up verification is recorded with its commit; no deploy, PR, or message occurred.
  • Retained-data final receipt: focused 2 files / 31 tests and root bun run verify 75 files / 682 tests passed with TypeScript and Vite; fresh local migrations 00010035 passed again. This supersedes the preceding child receipt's 681-test count without rewriting history. Docs/integrity checks and commit/push follow; no deploy, PR, or message occurred.

2026-07-16 — PR #196 P3 configured UI count supersession

  • The immediately following P3 receipt is preserved as historical append-only evidence, including its original 6 files / 31 tests statement. That historical count is superseded only by this dated correction.
  • Re-running its exact configured six-file UI command reports 6 files / 37 tests. The Package HANDOFF sentinel remains 1/1 and the previously recorded full bun run verify result remains 75 files / 669 tests.
  • This is a documentation-only release-truth correction: no runtime, user-visible copy, deployment, or release action changed.

2026-07-16 — PR #196 review P3 reproducibility truth correction

  • Corrected only append-only release documentation in the train worktree. The prior 6-files/52 focused receipt lacked a recorded reproducible command and is explicitly non-authoritative.
  • The authoritative configured UI command reports 6 files / 31 tests; the Package HANDOFF sentinel reports 1/1; full bun run verify remains 75 files / 669 tests. No runtime or copy changes were made.
  • No deployment occurred. Package reserve, exact-SHA staging, hosted acceptance, Stripe, and other owner gates remain unchanged.

2026-07-16 — train merge of exact main PR #223 (source truth; not deployed)

  • Train branch fast-forwarded to 7710eed3955a6c3643c67c3a19c2df2d6a859ebb and merged exact origin/main 4dc59090b3adbe78abedd20ca31283dc35e8251a normally with --no-ff --no-commit; this receipt preserves the Package/UI train history and the merged FHC #220/#222/#223 source-only truth.
  • FHC #220/#222 link-health and #223 sitemap-registry changes remain independently source-verified, not deployment proof. No runtime behavior was changed by this merge.

2026-07-16 — v60 mobile P1 target and Market confirmation-footer repair

  • Repaired the hostile-review mobile P1s on exact branch head bd681b9: the phone navigation trigger, authenticated account menu, referral pill, support launcher, support links, and support-close control now have effective 44px targets only at the mobile breakpoint. The existing desktop v60 geometry and all buyer-visible copy remain unchanged.
  • Reworked only the mobile Market purchase-sheet structure: details scroll in a body container and the existing confirmation action stays in a dedicated sticky bottom footer with a 44px action. A live local browser catch also showed the support launcher immediately closing through its outside-click listener; the opener now stops that opening event while outside-click dismissal still works.
  • Fresh exact-worktree local captures at 390x844 are docs/shots/v60-market-mobile-sticky-confirm-20260716.png, docs/shots/v60-mobile-targets-support-20260716.png, and docs/shots/v60-mobile-account-target-20260716.png. Computed local boxes recorded 44px targets, a position:sticky 390px-wide purchase footer, and scrollWidth: 390; this is not hosted/protected-staging acceptance. Focused regression proof passed 4 files / 18 tests; root bun run verify passed 75 files / 668 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; release JSON, conflict-marker scan, and git diff --check passed. Commit/push are next; no deployment, PR, merge, or message occurred.

2026-07-16 — v60 mobile P3 current-byte and support-focus repair

  • A hostile rereview first corrected current build truth to 422.45 kB / 133.92 kB gzip. The final exact P3 build, after support-focus restoration, emits initial JavaScript 422.60 kB / 133.95 kB gzip; deferred Leaflet is 150.05 kB / 43.58 kB gzip. Earlier dated 422.09 / 133.84 entries are historical measurements and remain append-only; the final P3 value is the current receipt.
  • Support now explicitly preserves internal dialog clicks, dismisses on an outside click, and restores focus to the existing Need help? launcher after dismissal. No buyer-visible wording, desktop token, deployment, PR, or provider behavior changed.
  • Cleanup correction: an orphaned exact-worktree Wrangler chain survived the prior cleanup despite no public 8793 listener. It and all remaining DevTools daemons were terminated; final command/cwd, 8793/5183 listener, and DevTools-daemon scans are empty. Focused proof passed 4 files / 19 tests; root bun run verify passed 75 files / 669 tests, TypeScript, and final Vite bytes above. Docs/JSON/diff/conflict scans, commit, and push are next.

2026-07-16 — v60 UI normal integration of merged Package HANDOFF train

  • Began a normal merge from pushed mobile UI head c33a90f29bbf5b7da74801a389425d348b57740e with exact incoming origin/orchestrator/marketplace-v60-20260713/merge 222030507ed3428af48c098c2979a9e4ac871377. The incoming merge contains PR #221's Package HANDOFF boundary child; it is merged into the train, not an open PR. The child adds the exact owner-block sentinel plus UTC-window and atomic-bulk rollback regressions, while leaving Territory-cap normalization owner-pending.
  • This is a source-only normal merge: no app/src UI source enters from the incoming range, Package 0033 and contact evidence 0034 retain their order, and no deployment occurred. Final verification/commit/push remain pending.

2026-07-16 — Package HANDOFF sentinel hostile-review repair

  • Restored the reviewer-detached worktree to branch codex/v60-package-reserve-handoff-boundaries at exact pushed child ae489252b0e021d754bf4fae5ed4cc298f3611c6. The former whole-document, whitespace-normalized threshold scan could pass when a duplicate ≥$250 string existed outside the locked owner block.
  • The sentinel now locates the exact Locked. Supply-reserve gate for Package activation: opening and subsequent ## Implementation status heading, extracts only that interval, and compares it with a checked-in exact multiline expectation. This includes the owner’s literal line wrapping and final blank line, so byte drift, deletion, or relocation outside that bounded block fails. No runtime Package, Territory, pricing, routing, migration, or UI behavior changed; Territory normalization remains blocked on Zak’s ruling.
  • Verification passed: focused 3 files / 23 tests plus app TypeScript; root bun run verify passed 72 files / 652 tests, TypeScript, and Vite build; bun run build:docs built 10 internal + 2 client docs; git diff --check passed. Root opened PR #221 for this branch, added Zak as reviewer, and texted him the PR/copy delta. PR #221 is not merged and nothing is deployed.

2026-07-16 — Package reserve locked handoff and boundary proof prepared

  • Created isolated branch codex/v60-package-reserve-handoff-boundaries from exact v60 train head 80f809e0b1e8362e99e8f598db21a569a4e0716d. The Package reserve handoff under docs/content/owners/zak/ now carries the exact owner-supplied locked block from Locked. Supply-reserve gate for Package activation: through This matches HANDOFF's 60% cap.; its existing title and separate implementation-status section remain outside the block.
  • Added test-only protection for the literal territory bids that cover Hot, ≥$250 threshold (with whitespace normalization only in the assertion because the locked source wraps that phrase across two lines), UTC start-inclusive/end-exclusive readiness and activation-reservation regressions, and a failBatchStatementContaining = 'INSERT INTO market_purchases' bulk fault proving rollback restores the pre-existing fixture baseline with no new debit, batch, purchase, claim, portfolio, lead, or buyer-counter state.
  • Verification passed: focused 3 files / 23 tests plus app TypeScript; bun run build:docs built 10 internal + 2 client docs; full root bun run verify passed 72 files / 652 tests, TypeScript, and Vite build; git diff --check passed. The known resilience-test stderr is expected forced-failure coverage, not a suite failure. A separate non-runtime child commit contains only this handoff/proof/docs slice. No Package/Territory reserve arithmetic, normalization, migration, routing, pricing, UI, deployment, PR, or owner message occurred.
  • Next up: wait for Zak’s Territory normalization ruling, then add one shared, fail-closed territory-demand contract to both scheduler readiness and transactional prospective-reserve enforcement; do not infer a weekly_cap money rule before that lock.

2026-07-16 — FHC PR #219 merged into the Package #218 train

  • Began a normal merge from exact Package train 0b86a6945439ee1447d77851e86d1b576cbb44dc and exact FHC PR #219 d06e30936220729bb73881efbc276766e3c92952. Package app/ and migration 0033 are conflict-free; #219 contributes only FHC source/guard/data/report paths and shared documentation.
  • Shared ledger/index/roadmap/walkthrough conflicts were resolved additively: Package #218 history remains intact, the restored #217 fhc-10 plan remains verbatim and planning-only, and #219's nine strict guard/source paths match exact d06e309. The complete FHC subtree intentionally retains two preexisting v60 canonical-acquisition additions in src/soldi-ingest*, which #219 did not touch. #219 remains source-only with no FHC deployment or public-output claim. Verification passed: root bun run verify 71 files / 648 tests, TypeScript, and Vite; FHC 457 tests / 10 files, fresh 965-page build, and audit; docs build, release JSON parse, Package/FHC/path/hash identity checks, conflict-marker scan, and git diff --check. Commit, push, and PR #196 observation are pending. No deployment, provider action, PR merge, or Zak message occurred.

2026-07-16 — Package branch normal merge of exact FHC/train head

  • Merged exact origin/orchestrator/marketplace-v60-20260713/merge 61598bc57d5282b644c64a68cce7fe9f92ccf9bf normally into the Package repair head a5f5773a881b8b74eacb775abd03f0c8be8f5a8f. Only shared ledgers/index/implementation-note history conflicted; their resolutions retain Package sessions plus FHC PR #214/#216 train history and Zak's verbatim, planning-only FHC-10 restoration from #217. App code and migration paths had no semantic conflict.
  • Post-merge proof passed: Package-focused 10 files / 117 tests plus app TypeScript; root bun run verify 71 files / 648 tests, TypeScript, and Vite build; FHC 447 tests, a fresh 965-page build, and audit; docs built 10 internal plus 2 client docs; release-readiness JSON parsed; conflict-marker and diff checks passed. No deployment, PR merge, or Zak message occurred.
  • Next up: commit/push this normal merge for PR #218 re-review. Package remains held behind protected exact-SHA staging proof; FHC #217 remains planning-only.

2026-07-16 — Package strict staged-gate P1 closure locally verified

  • Second hostile review of fb97d99 found a missing/unknown environment could accept a forged staged-ready row, while writeCycle disabled its reserve predicate outside exact staging. packageFulfillmentReady now permits Package only when APP_ENVIRONMENT is literal staging, PACKAGE_READINESS_SCHEDULER_ENABLED is literal true, and the attested staged-ready row exists. Undefined, arbitrary, test, development, and production all fail closed.
  • Removed the transaction's environment-dependent reserve toggle: every billing/renewal path that passes the strict shared gate executes live supply/demand/prospective-cap SQL. The SQLite helper now explicitly opts Package tests into staging and installs canonical fixed-window Hot/PPC supply; it does not create a runtime test bypass.
  • Added forged-ready no-mutation regressions for undefined, arbitrary, literal test, production, staging-missing-scheduler, and staging-false-scheduler configurations. Each leaves zero Package cycle, activation reservation, and wallet debit. An unset-environment due renewal preserves its current/predecessor cycle, one reservation, one debit, and balance; unset-environment routing creates no Package delivery or fulfillment claim and resolves to Open Market. Valid staging start/renewal proof remains covered. Focused Package plus shared-helper regression proof passed 10 files / 117 tests with app TypeScript. Full root bun run verify passed 71 files / 648 tests, TypeScript, and Vite build; expected forced-failure/resilience stderr was exercised test coverage, not a verification failure. No remote migration, deployment, PR, merge, or Zak message occurred.
  • bun run build:docs built 10 internal plus 2 client docs and git diff --check passed.
  • Next up: commit/push and stop for rereview.

2026-07-16 — Package renewal reserve P1 closure locally verified

  • Exact-head hostile review of e40cf4f found that the activation-reservation SQL could count a renewing Package as existing paid demand and add prospective +25. At 50 current Hot/PPC leads (capacity 30), that could compute 50 and reject a valid one-Package renewal. The reservation now excludes only the exact (user_id, predecessor_cycle_id) passed by the authorization predicate, so the renewal records its post-renewal 25-lead commitment while a start still counts all existing commitments.
  • Added staging-mode end-to-end SQLite proof: one active 25-lead Package at 50 supply, readiness recomputed for the due window, one paid successor/current subscription, successor reservation 25/50, two Package charges total, and no extra cycle/debit after a delayed replay. Corrected the stale Wrangler comment: production explicitly binds APP_ENVIRONMENT=production; undefined remains defensive fixture fail-closed behavior.
  • Focused Package reserve/billing/cancellation/successor proof passed 4 files / 30 tests with app TypeScript. Final root bun run verify passed 71 files / 640 tests, TypeScript, and Vite build; expected forced-failure/resilience stderr was exercised test coverage, not a verification failure. No remote migration, deployment, PR, merge, or Zak message occurred.
  • bun run build:docs built 10 internal plus 2 client docs and git diff --check passed.
  • Next up: commit/push the corrected Package branch and stop for rereview.

2026-07-16 — Package hostile-review closure rebased over backend integrity

  • Rebasing codex/v60-package-readiness-atomic-market from held ee77ddb onto exact merged backend-integrity head 6f38cc1930f7c0f4638355ac6eb9a01e5692802d preserved target 0032_v60_data_integrity.sql and renamed the forward Package/Market migration to 0033_package_readiness_and_market_batches.sql. No historical or merged migration was rewritten.
  • Package activation now creates an immutable package_activation_reservations row in the same D1 batch before a cycle can transition from pending to paid. Its SQL rechecks the exact staged readiness authority, current 30-complete-UTC-day Hot/PPC denominator, valid current paid commitments, and prospective +25 against the locked 60% cap. The paid-cycle trigger rejects a transition without the reservation, so two starts against 50 current Hot/PPC leads admit one 25-lead Package and roll the other transaction back with no partial charge or ownership.
  • Added immutable update/delete guards for package_readiness_decisions; recomputation rechecks the literal scheduler binding before publishing state. package-router.ts now shares billing's production/staging scheduler gate before Package eligibility or fallback evaluation, so a production copied/stale ready row cannot route Package inventory and routes through normal Market fallback instead.
  • Rebased the atomic 2–25 lead Market path onto the merged canonical Investor-only bucket contract. The batch guard and preflight now reject a pre-existing Market owner as well as claims/auctions; canonical Cold/Warm/Hot prices remain $90 / $150 / $250, Hot remains full price, and only the documented aggregate Cold/Warm ladder affects a batch total. Bulk remains independently mergeable, non-blocking, and UI-disabled.
  • Focused real-SQLite proof passed 4 files / 54 tests: reserve overcommit race, scheduler disable during recomputation and before activation write, production stale-ready routing, immutable decision mutation/delete rejection, bulk replay/concurrency/insufficient-funds/already-owned, billing, and routing. App TypeScript and git diff --check passed. No migration was applied remotely, no Worker deployed, no PR opened, and Zak was not messaged.
  • Final root bun run verify passed 71 files / 639 tests, TypeScript, and Vite build; bun run build:docs built 10 internal plus 2 client docs and git diff --check passed. Expected forced-failure/resilience stderr was exercised test coverage, not a verification failure.
  • Next up: push for hostile re-review. Package still needs protected exact-SHA staging scheduler/readiness/start/renew/delivery proof. Bulk UI remains disabled until reset-isolated hosted atomic purchase proof and UI-lane evidence.

2026-07-15 — Package reserve gate and atomic Market batch backend locally verified

  • Added unapplied migration 0032_package_readiness_and_market_batches.sql. Package reserve records immutable, auditable staging decisions with the 30 complete UTC-day window, committed Hot demand (25 leads per active Package), observed Hot/PPC supply, result, and reason. Missing calendar days contribute zero; malformed PPC supply or Package state fails closed. The only enabling authority is the Worker scheduled caller scheduled-package-readiness-v1; production now declares APP_ENVIRONMENT=production and remains disabled by default, while staging still requires an explicit PACKAGE_READINESS_SCHEDULER_ENABLED=true binding before it can create a ready state.
  • Added backend-only POST /api/v1/market/leads/purchase for 2–25 selected leads with an idempotency key. It claims all leads, creates one immutable market_batch wallet debit, and then completes ownership, portfolios, delivery, and fulfillment guards in one D1 batch. A database trigger rejects incomplete, duplicate, stale, non-canonical, wrong-vertical, already-claimed, unaffordable, or budget-breaking batches before any partial economic state can commit. Canonical per-lead prices remain Cold $90, Warm $150, Hot $250; only PR #193's documented Cold/Warm 3+/5+/10+ ladder affects the aggregate batch total, so Hot remains full price.
  • Focused real-SQLite proof passed Package policy/replay/scheduled-caller, Package routing, legacy direct Market, and bulk concurrency/replay/insufficient-balance/already-owned cases. After control PR #213 merged, the lane fast-forwarded to exact head 515a0a807ec677eada43ed0736f35d182ee13b74, preserved its readiness artifacts, and reran root bun run verify: 69 files / 595 tests, TypeScript, and Vite assets/index-BiQwcHs_.js; git diff --check passed. Expected forced-failure test stderr remained non-failing test evidence.
  • No migration was applied remotely, no Worker was deployed, and no buyer UI, checkbox behavior, Hot-full-price copy, or bulk tier-tease copy changed. Bulk backend is independently mergeable but is not a promotion gate; Package reserve remains a promotion gate.
  • Next up: on a protected staging environment serving the exact commit, apply 0032, set the staging-only readiness binding, run the scheduled caller against real auditable supply without fabricating data, and prove Package start/renew/delivery remain disabled until the recorded 60% reserve passes. Run reset-isolated batch purchase/replay/concurrent-buyer proof there before any UI bulk activation.

2026-07-16 — Zak FHC editorial-plan restoration reconciliation

  • Created a normal merge from exact train dc3a193f89a77befedd9b185dc13efb24d8029a3 and exact origin/main PR #217 1d1af89cb73d21d8f9ad572a155c7da59b979d60. The only incoming source file is sites/fhc-pages/reports/fhc-10-editorial-plan.md; its post-merge SHA-256 matches exact origin/main, so the restored plan is verbatim.
  • Recorded #217 as planning-only context in current readiness and the append-only train note/index. It changes no FHC/Soldi code, launch gate, provider state, or deployment authority. Verification passed: root bun run verify 69 files / 627 tests, TypeScript, and Vite; FHC 447 tests, fresh 965-page build, and audit; docs build, release JSON parse, verbatim-plan hash comparison, conflict-marker scan, and git diff --check. Push and PR #196 observation are pending. No deployment occurred.

2026-07-16 — marketplace v60 master-train reconciliation

  • Fast-forwarded the master train to exact remote 6f38cc1930f7c0f4638355ac6eb9a01e5692802d, then created a normal merge with exact origin/main 00c296ab297a80299f1ea6230bfa18e1d0d794c6. The merge retains all v60 backend-integrity/master-readiness sessions and imports PR #214's live FHC code plus PR #216's Zak freshness/superseded-claims reports and FHC CI bun test step.
  • Resolved shared docs additively: BUILD_LOG.md and implementation-note history were not rewritten; the v60 walkthrough retains its six-screen candidate and restores the live FHC seller-funnel slide with current #214/#216 status. CURRENT_MVP_READINESS.md and release-readiness.json mark only the completed FHC current-main integration PASS; all Soldi staging, Stripe, retained-data, hosted-final-SHA, review, and promotion gates remain held.
  • Verification passed: root bun run verify 69 files / 627 tests, TypeScript, and Vite; FHC 447 tests, fresh 965-page build, and audit; docs build, release JSON parse, conflict-marker scan, and git diff --check. The normal-merge commit is created; push and PR #196 check observation are pending. No deployment occurred.

2026-07-16 — consolidated MVP launch-control reset

  • Reconciled Zak's authoritative 2026-07-16 Soldi handoff and locked follow-up rulings into docs/plans/mvp-build-public-release/CURRENT_MVP_READINESS.md, the packet's human/machine decision surfaces, and the living v60 implementation note. Older July 6 beta status is explicitly historical.
  • Closed the retracted missing-transaction finding, approved Agent-mode and two-step-sign-in deviations, made bulk non-blocking but visibly gated, locked budget presets plus flexible controls, and defined Make offer as an editable calculator-prefilled activity/stage transition.
  • Started five pinned Terra/high implementation lanes plus a direct-chat-only iMessage monitor and a separate imsg stream --lookback improvement lane. No group chat, database migration, Stripe mutation, DNS change, or deployment occurred.
  • Confirmed both production soldi and soldi-staging expose active D1 Time Travel bookmarks. Restore retention/drill, exact served-SHA provenance, protected staging, Stripe sandbox acceptance, retained-data preflight, hosted desktop/mobile QA, and rollback proof remain launch gates.
  • Verification on exact control base 52040eb: bun install --frozen-lockfile; bun run verify passed 67 files / 588 tests, TypeScript, and Vite assets/index-BiQwcHs_.js; packet JSON and git diff --check passed.
  • Next: merge the readiness-control PR into #196, land and adversarially review the UI/data/Package/provenance children, land/deploy the separate current-main FHC integration, configure protected exact-SHA staging, and promote only after the canonical acceptance packet is green.

2026-07-15 — v60 backend/data integrity lane locally verified

  • Added forward migration 0032_v60_data_integrity.sql: it archives/redacts synthetic placeholder contacts, canonicalizes the four buyer situations without renaming legacy IDs, and seeds the fictional Investor-only U_DEMO_V60 profile.
  • Reconciled the demo statement exactly: $5,000.00 funding less $90.00 + $150.00 + $250.00 typed Open Market purchases equals $4,510.00; every pre-owned demo lead has a typed purchase, portfolio/stage, delivery, and ledger row. No activation rows are seeded.
  • Removed current worker output/generation for quality, held balance, live-transfer/recording, and source-bucket residue; locked refunds to the nine approved shared enum values; exposed Territory position; and rejected Hot claims under $250.
  • Verification after the target-head integration: focused 8 files / 130 tests, final disposable local D1 migrations 00010032 with 0 placeholders / 451000 demo cents / 3 purchases / 0 activation rows / 0 recording-note residue, and root bun run verify 68 files / 592 tests, TypeScript, Vite assets/index-BdJy0tCO.js; docs build passed. No deployment or remote D1 operation occurred.

2026-07-16 — v60 buyer marketplace deployed to staging for Zak review

  • Stood up the soldi-staging review environment: added env.staging to app/wrangler.jsonc (worker soldi-staging, workers.dev only, no soldi.cc route) bound to an isolated remote D1 (soldi-staging, id 516586fe…). Never touches prod worker soldi / prod D1 / app.soldi.cc.
  • The pre-provisioned staging D1 carried a drifted double migration lineage (old 0026_refund_transaction_integrity etc. layered under the current v60 names → 0029 collided on refund_request_claims, demo user absent). Recreated the throwaway scratch DB clean and applied 0001–0031 fresh: 10 users, 65 leads, demo@soldi.cc restored.
  • Built the merge tip (3aa9251) in an out-of-repo sandbox (repo node_modules are macOS-owned), deployed wrangler deploy -e staging → version 5dc8894e. Secrets set on -e staging: SESSION_SECRET (fresh), FHC_INGEST_SECRET, Stripe test-mode placeholders (STRIPE_EXPECTED_MODE=test).
  • Live proof at https://soldi-staging.camolechowski.workers.dev: /api/v1/health 200; anon /auth/me {user:null}; /auth/demo 302 → session; authed /auth/me = demo@soldi.cc ($1,000 wallet); /market/leads 11 rows with source-based pricing; /pipeline staged cards + seller contact. Browser: Open Market + Payment & Budget render Zak's f8b192b 1:1 — tier pills, $90/$150/$250 in-table, deposit bonus tiers, three-ways-to-buy; Package shows gated ("Activation opens after automatic fulfillment routing is installed"). Zero console errors.
  • Still gated before real buyers (unchanged): supply-reserve Package activation, server-atomic bulk buy, delivery dispatch — all render disabled/parked. Auctions/realtime parked (AUCTIONS_ENABLED=false).
  • Sent Zak (DM only) the staging URL + demo login to confirm his UI + backend wiring. Not merged to main; prod app.soldi.cc untouched.

2026-07-15 — Zak v60 six-screen fidelity correction

The shipping app now ports the pinned f8b192b v60 buyer mock as one cohesive product instead of translating it through the older app shell. The buyer contract is Open Market, Payment & Budget, My Leads, Transactions, Territories, and Settings with literal v60 colors/type/density, the compact navigation and help/referral utilities, canonical four-situation vocabulary, fixed Cold/Warm/Hot pricing, and no public competition, retired buyer-route, or realtime-buyer layer. Direct legacy URLs redirect into the v60 spine and the corresponding public worker endpoints were removed.

The port preserves backend truth: My Leads has ownership-scoped persisted notes and real event history plus revenue and wholesale calculations, and its Package tag/filter derives from an ownership-matched package_deliveries record in the real pipeline response; Territories shows real situation-scoped trailing-30-day classified volume and the highest active bid. Zak's PR #209 locks Package eligibility at committed Hot demand no greater than 60% of 30 complete Hot/PPC supply days, with each Package counting 25 and cold-start missing days counting zero. Activation stays unavailable until that rule and the staged caller are implemented/proven. Transactions Resend, Settings notification/delivery/test-lead controls, and multi-lead purchase remain explicitly unavailable pending their delivery or atomicity contracts. Zak received the buyer-visible copy/functional delta before merge.

Verification: mandatory Sol/medium and Terra/high polish/simplify passes completed; focused Package attribution proof passed 5 files / 31 tests, including real SQLite Package routing into the authenticated pipeline. The first full-range exact review then rejected candidate 6dcc205 for two blank mobile receipts, legacy buyer client/taxonomy contracts, situation-insensitive Territory context, and stale Package-policy docs. The remediation passed 9 files / 60 tests, app TypeScript, client-vocabulary and <400 scans, then final bun run verify passed 66 files / 582 tests, TypeScript, and Vite assets/index-C58kQCpa.js; bun run build:docs built 10 internal + 2 client docs + index; git diff --check passed. Local browser QA covered all six routes at 1440×900 and 390×844 with no page overflow, retired visible/accessibility vocabulary, or console errors. The two mobile receipts were recaptured after the source graph settled, and a measured 390px mock comparison additionally corrected the Open Market table from forced horizontal scrolling to the mock's natural clipped composition before accepting the final image. Twelve dated local candidate captures live under docs/shots/v60-*-20260715.png; they are evidence for this branch, not deployed proof.

Next: commit the exact candidate, obtain fresh exact-head Sol/medium and Terra/high read-only verdicts, open the single ready PR against the v60 launch train with killerabbasi requested, and merge after QA. Promotion remains frozen until canonical staging is provisioned at the exact merged SHA and passes reset-isolated Stripe, import, purchase, refund, security, desktop, and mobile acceptance.

2026-07-15 — Admin import and Package routing exact-review remediation

  • Remediated committed import/routing head a82abe06c763de235d374e982037c46d03f1d939 without amending it. Sol/medium and Terra/high had rejected that head for D1 resource exhaustion at 100 rows, Package terminal replay, and a Territory-priority race; the fixes remain a separate follow-up commit.
  • Replaced unbounded per-row duplicate/price-band reads and five writes per row with set-based preflight plus a nine-statement json_each() transaction. The maximum-size regression imports 100 rows with at most 16 total test-D1 operations. Raw JSON is streamed and rejected before parse above the worst-case envelope for the decoded 1 MB CSV limit.
  • Package reservation, completion, and Market fallback now atomically exclude every currently eligible Territory order using the canonical active/account/wallet/budget/week/bid/filter contract. Package buyers must also satisfy the complete canonical investor profile. Terminal Package allocation replays the same portfolio without requiring a Territory standing-order ID.
  • Added forced post-reservation rollback, repeated Admin approval, malformed Package profile, newly eligible Territory, expired processing/finalizing recovery, terminal replay, and no-Market-leakage real-SQLite coverage. Recovery now permits an expired finalizing no-winner claim to resume the Package/Market waterfall while protecting debited/committing Territory money states.
  • UI success and refresh are separate truths: a committed receipt remains successful if the Admin queue refresh fails, with one distinct reload advisory. The inline confirmation no longer claims modal semantics. Direct UI proof passed 7/7; focused backend proof passed 5 files / 25 tests.
  • Real Worker-backed local browser QA passed the non-mutating Admin interaction at 1440×900 and 390×844: keyboard confirmation/Cancel, exact sample preservation, zero import batches, and no overflow. The fresh dated screenshot is docs/shots/admin-supply-import-20260715.png.
  • The same browser pass found a separate staging blocker: with the required default AUCTIONS_ENABLED=false, the global ticker repeatedly opens the parked floor WebSocket, producing 15 HTTP 410 console errors. An AUCTIONS_ENABLED=true isolation control made the Admin pages console-clean, but does not replace the default-off finding; a narrow client-socket child must land before hosted zero-console acceptance.
  • Fresh bootstrap applied migrations 00010031; root bun run verify passed 59 files / 553 tests, TypeScript, and Vite assets/index-Mb9NuFr6.js; git diff --check passed. The Admin identity fence is deliberately scoped to Admin CSV, and package_fulfillment_state remains disabled pending supply-reserve policy and staged-caller proof.
  • Follow-on exact review found three P1 seams in that proof: SQLite's ASCII-only lower() diverged from JavaScript for valid Unicode Territory filters, finite raw/full-width historical candidate expansion was not complete NFKC duplicate safety, and stale finalizing recovery trusted a persisted Territory order without rechecking its current bid/filter/economic eligibility.
  • Corrected migration 0031 in place because it remains unshipped. Leads and Standing Orders now persist application-owned NFKC/case match keys. Package reservation, completion, and Market fallback use one shared current-Territory SQL expression; inspection and reproduced failure proved its lead-ID placeholder preceded the weekly-cap time placeholder, so shared bind helpers now follow the actual SQL order. Legacy uncanonicalized Territory rows fail closed rather than leak to Package/Market.
  • Every current lead ingress writes one canonical property_identity_key. Admin CSV compares that indexed key directly and stops before writes if any historical lead lacks one, avoiding incomplete compatibility-form enumeration while keeping the returned legacy probe bounded to one row.
  • Expired finalizing recovery now revalidates the persisted order against current filter, bid, wallet, monthly budget, and weekly cap before debit. An invalid winner is released to processing, then the current winner is selected or the Package/Market waterfall resumes; existing debited and committing safety remains unchanged. Real-SQLite proof covers bid, wallet, budget, cap, filter, no-winner, concurrent replacement, and protected money-moved recovery.
  • Root review caught and removed an ASCII post-insert trigger that lowercased raw Territory values without application-equivalent trim/whitespace collapse, then tightened the existing-row migration backfill to printable, already-trimmed ASCII with no doubled spaces. Missing or unsafe keys remain null and fail closed. Final focused proof passed 7 files / 52 tests, including post- and pre-0031 whitespace rows with zero Package/Market writes and unchanged ownership. Fresh bootstrap applied 00010031; full bun run verify passed 60 files / 572 tests, TypeScript, and Vite assets/index-Mb9NuFr6.js; docs built 10 internal + 2 client docs + index. Migration 0030 retained SHA-256 5f50c65cd754f122f13ba9f2a6619d277529e3fe80d7b987ee7df7237ef728b6; diff, secret, staging, and under-400-line hygiene passed. No app UI changed, so the existing dated Admin screenshot remains accurate; no deploy, commit, push, remote database, or Stripe operation ran.
  • Exact-head follow-up at 63d69769f0bd57cdc2f6bce0c0a11fb72e109045 removed raw state from Package eligibility and candidate binding. Reservation and completion now compare validated buyer markets to persisted territory_state_key; lower, mixed-case, surrounding-whitespace, and full-width raw states all Package-deliver and terminally replay with zero Market reservation/decision.
  • Property identity is now a compact canonical JSON tuple rather than delimiter concatenation. Migration 0031 safe-backfills that exact encoding, deliberately aborts on safe-key duplicate groups, and creates a partial unique index over every non-null key. The fence is global across FHC, manual, and CSV writers; route conflicts return honest 409 responses, and a failed signed FHC duplicate releases its unused event claim. Unsafe/null history retains the explicit Admin-import backfill gate.
  • Production/staging gate: run the read-only admitted-subset duplicate preflight before 0031; after application, use application-owned NFKC code to backfill remaining null keys under the unique index, resolve every surfaced collision, and prove zero null keys before Admin import can proceed. Package fulfillment remains disabled independently.
  • Final proof passed the exact prior seven-file selection at 61/61 tests (up from 52), then root bun run verify at 60 files / 581 tests, TypeScript, and Vite assets/index-BNeffjG7.js. Fresh local bootstrap applied 00010031; the resulting database had the partial unique fence and zero package_fulfillment_state rows. Docs built 10 internal + 2 client docs + index. Migration 0030 retained SHA-256 5f50c65cd754f122f13ba9f2a6619d277529e3fe80d7b987ee7df7237ef728b6; diff, secret, and under-400-line changed-source checks passed. No commit, push, deploy, remote mutation, or staged change occurred.
  • R5 exact review closed the signed FHC idempotency gap. Migration 0031 deletes historical event rows with no durable lead, then adds explicit processing|completed state with surviving history defaulted completed. New claims are processing; the lead/consent/audit transaction completes the exact event as its final statement. Completed replay requires its lead, while concurrent/fresh processing and unreconciled orphans return retryable 409, never a phantom ID.
  • Every claimed lead-batch exception now attempts exact processing-claim cleanup. Property conflicts retain honest 409; other pre-commit failures rethrow only after release, and after-commit ambiguity preserves the completed event because its lead exists. A conservative 10-minute received_at lease reclaims only exact stale processing rows without a lead; fresh, invalid-timestamp, and durable-lead claims fail closed. Real-SQLite proof covers concurrent replay → first rollback/cleanup → same-event success, completed replay, after-commit ambiguity, historical/post-migration orphans, and fresh/stale/durable lease behavior.
  • R5 final proof passed the exact seven-file selection at 65/65 tests, fresh bootstrap applied 00010031, and root bun run verify passed 60 files / 585 tests, TypeScript, and Vite assets/index-BNeffjG7.js. Docs built 10 internal + 2 client docs + index; migration 0030 retained SHA-256 5f50c65cd754f122f13ba9f2a6619d277529e3fe80d7b987ee7df7237ef728b6; diff, secret, staged, and changed-source line hygiene passed. No commit, push, deployment, or remote action occurred.
  • Reconciled the import candidate with launch-train parent 0e73669452c702ec44206b103471e87066763c9a, preserving the independently reviewed realtime remediation and both append-only histories. Post-merge bun run verify passed 64 files / 611 tests, TypeScript, and Vite assets/index-DawYam7T.js; docs built 10 internal + 2 client docs + index and staged diff hygiene passed. No hosted or deployment claim is implied.
  • Final exact-review remediation replaces the signed-event zero-change completion update with an immutable fhc_ingest_completions generation guarded by migration triggers. The assertion is the final statement in the lead/consent/audit D1 batch: an owner superseded after live stale-lease takeover raises fhc_ingest_ownership_lost and rolls back all success writes; the valid owner completes exactly once and later replays 200 duplicate:true. Completion identity is (event_id, lead_id), preserving immutable old proof while allowing the existing completed-orphan reconciliation path to reclaim an event under a new lead generation.
  • Expired processing and finalizing Territory recovery now carries persisted acquisition_source into source-filter matching. Real SQLite proves PPC/organic-as-inbound produces one Territory debit/delivery and zero Package/Market reservation or decision rows.
  • Red-first proof failed the live takeover and both source-filter recovery cases, and separately reproduced the first completion schema stranding completed-orphan reclaim. Final focused proof passed 7 files / 69 tests; fresh bootstrap applied 00010031 with zero fulfillment/enabled rows, zero property-key nulls, the partial unique property index, and the completion ownership trigger. Root bun run verify passed 64 files / 615 tests, TypeScript, and Vite assets/index-DawYam7T.js. The earlier realtime ledger line and blank separators were restored byte-for-byte to the launch-train parent.
  • Final r7 review found no runtime, migration, or money-path defect. Terra/high returned READY after an additional three-generation completed-orphan probe; Sol/medium rejected only the strict file-hygiene gate because candidate-owned admin-territory-allocation.test.ts was exactly 400 lines, and reported two stale-doc nits. The narrow follow-up compacted one adjacent pair of test-harness fields to 399 lines without changing coverage, dated the changed Supply Side PRD 2026-07-15, and replaced the walkthrough's already-completed socket source task with the remaining exact-SHA zero-network/console-noise acceptance gate.
  • Post-correction proof passed the exact 7-file / 69-test selection and root 64-file / 615-test verify, TypeScript, Vite assets/index-DawYam7T.js, and the 10 internal + 2 client docs + index build. The complete candidate line scan now tops out at 399 lines, 0030 retains SHA-256 5f50c65cd754f122f13ba9f2a6619d277529e3fe80d7b987ee7df7237ef728b6, and diff/secret-shape hygiene passed. Direct make-it-sexy then make-it-simpler review preserved the existing walkthrough visual system and reduced the correction to one current acceptance sentence; no app or public seller/buyer copy changed.
  • Next: fresh exact-head review/CI. Keep Package fulfillment disabled until the supply-reserve policy and staged-caller proof are resolved; the default-off client floor socket is closed by the separately merged realtime remediation below.

2026-07-15 — Exact-head realtime review remediation 2

  • Started clean from committed local-source head f25eb5a85038fb0f00b294506bb5b750999e5475 and implemented every P1/P2 in the Sol and Terra exact-head rejection receipts without touching the server gate. Capability checks now retain only one concurrent in-flight request; every new room/topic effect and every reconnect obtains a fresh parsed health result, and only literal boolean auctionsEnabled: true can construct a socket.
  • Bound connection truth, event history, and the WebSocket reference to the exact topic key. A topic change immediately exposes Checking/Linking with empty events, rejects sends through the prior room's socket, and resets ChatPanel messages, presence, hello seeding, and draft state. Drafts intentionally survive capability/socket transitions within one auction but clear when auctionId changes to prevent cross-room intent leakage.
  • Chat is sendable only when capability is enabled and the exact-topic socket reports open. Checking, connecting, degraded, and parked inputs/buttons are disabled; send returns acceptance and a failed/racing delivery leaves the draft intact.
  • Deleted the unused fabricated MOCK_TICKER fixture. The ticker marquee now exists only while connected and only after verified floor frames arrive; Checking, Parked, and Linking retain their neutral status messages, while an open room with no verified events says No auction activity yet.
  • Exact visible copy deltas: checking composer Message the room…Checking chat availability…; enabled/connecting composer → Connecting to auction chat…; enabled/degraded composer → Reconnecting to auction chat…; open/no-event ticker → No auction activity yet. Parked Auction chat is paused., ticker Checking/Parked/Linking/Live labels, and their existing status sentences remain unchanged.
  • Direct make-it-sexy review preserved Zak's font, token, density, status-frame, spring, and reduced-motion language with no redesign. Direct make-it-simpler reuse/quality/efficiency review removed the now-dead fixture, retained the shared apiGet('/health') owner, coalesced only concurrent checks, keyed state instead of adding caller-specific gates, and added no recurring polling or redundant work.
  • Verification: focused capability/realtime/chat/ticker proof passed 4 files / 26 tests. Full bun run verify passed 58 files / 549 tests, TypeScript, and Vite assets/index-CBSuz7Uh.js; docs build and diff hygiene passed. Final secret-shape and changed TypeScript/TSX line gates also passed.
  • Next: exact-head rereview, then exact-served-SHA staging/browser proof. No commit, push, deploy, remote mutation, or hosted claim occurs in this remediation.

2026-07-15 — Default-off realtime remediation after polish/simplification review

  • Read the mandatory reuse, quality, and efficiency receipts before editing the uncommitted realtime gate. Replaced its second raw fetch pipeline with the shared apiGet<unknown>('/health') boundary; the capability reader now owns only literal-true interpretation, fail-closed rejection handling, and shared request lifecycle.
  • Corrected compatibility truth: a room starts and remains connecting while the health capability is unresolved, so existing status-only consumers such as ChatPanel render Linking/loading rather than a false Offline state. Resolved false/unavailable capability remains degraded and constructs no socket.
  • Reconnect now centrally revalidates the shared capability before constructing another WebSocket. A previously true long-lived tab converges to parked when a subsequent health result is false; simultaneous callers share the in-flight refresh instead of fanning out health reads.
  • Ran the required direct make-it-sexy review before the direct make-it-simpler review under the no-subagent constraint. The ticker retains its existing restrained, reduced-motion-safe presentation and accessible status region; the remediation introduces no decorative visual churn. Simplification retained the distinct capability/status states because deployment authority and socket health are separate, and made the retry test deterministic.
  • Zak-facing visible copy now stays exact: ticker uses Checking / Checking auction activity status., Parked / Buyer auction activity is paused., Linking / Auction activity is linking., and Live / Auction activity is live.. Parked chat uses Parked, Auction chat is parked., and Buyer auction activity is paused.; its composer placeholder becomes Auction chat is paused. and is disabled without clearing a typed draft. The prior Offline, Room offline., and Reconnecting to the floor… wording remains only for a real degraded socket after capability has been enabled.
  • Verification: focused capability/realtime/ticker/chat proof passed 4 files / 16 tests. Full bun run verify passed 58 files / 539 tests, TypeScript, and Vite assets/index-D83LrtWy.js; bun run build:docs passed and git diff --check was clean. No commit, push, deploy, remote, or screenshot recapture occurred.
  • Next: root review/commit integration, then repeat default-off and true-to-false reconnect browser/network proof against the exact served staging SHA. No hosted claim is made by this local receipt.

2026-07-15 — Default-off realtime client capability gate

  • Started from exact v60 integration head 771d1f122a4a6e6c37a7e1005bfe6ff9ed371ab2 on codex/v60-realtime-default-off. The server-side 410 and exact-string AUCTIONS_ENABLED contract remain unchanged.
  • Added one cached /api/v1/health capability read shared by all useRoom callers. Only an OK payload with literal auctionsEnabled: true permits new WebSocket; false, absent, malformed, non-OK, and rejected health reads all park floor and auction sockets before construction.
  • Kept enabled realtime reconnect/history behavior intact and made pending-health/unavailable lifecycle cancellation-safe. A health result arriving after unmount cannot update state or open a late socket.
  • The global ticker remains in the layout but hides seeded auction activity until capability is proven. Default-off and indeterminate states now show a neutral Parked / Buyer auction activity is paused. state instead of browser handshake errors or promotional copy.
  • The repo's historical polish workflow could not run as written because it delegates to agents and its four local group skill directories are absent. A direct make-it-sexy pass retained the established refined ticker, tokens, layout, and reduced-motion behavior; the required subsequent direct make-it-simpler pass removed disabled-state marquee work and found no further justified abstraction.
  • Focused capability/realtime/ticker proof passed 3 files / 10 tests. Full bun run verify passed 57 files / 533 tests, TypeScript, and Vite assets/index-TybY-1Xh.js; every touched TypeScript/TSX file is under 400 lines and git diff --check passed. Local browser evidence showed one health request, visible parked copy, and no /api/v1/rt/* request for the isolated page. No commit, push, deployment, PR, or remote application-service mutation occurred.
  • Next: root review/commit integration, then repeat the default-off browser console/network check at the exact served staging SHA. The enabled-path unit proof is green; no hosted or deployed claim is made here.

2026-07-15 — Package final correction: exact successor ancestry and replay truth

  • Continued the uncommitted correction above rejected Package head 29e4d7a on codex/v60-persisted-package-billing; no prior commit was amended and no remote, deployment, commit, or push occurred.
  • Added nullable unique package_cycles.predecessor_cycle_id, populated only from the expected subscription cycle in renewal writeCycle and protected by cycle immutability. All three early successor settlement authorization boundaries and migration 0030's economics trigger now require the persisted predecessor link, same user, exact observed/end-to-successor-start boundary, and predecessor due at settlement time.
  • Added real SQLite adversarial coverage for foreign, mismatched, self/non-adjacent, future-due, and same-user exact-boundary look-alike intents; none can settle or mint a shortfall credit. The legitimate predecessor remains recorded and the one-delivery renewal-before-intent race credits only $4,800 before successor cancellation.
  • Added direct absent-readiness proof for renewal and delivery; structured 402 Package start envelopes now survive the API boundary and Billing distinguishes immutable payment_required replay from later active or cancellation-pending current truth without a false activation/Add $0 claim.
  • Split scheduled, Market, and settlement test responsibilities into small fixture/case modules; the strict base-to-working-tree TypeScript/TSX line gate is rerun at closeout. The direct make-it-sexy then make-it-simpler pass kept the existing refined Billing system, focus trap/return-to-opener, reduced-motion behavior, and state-specific truthful copy.
  • Fresh bootstrap first encountered local SQLite SQLITE_IOERR_SHMSIZE with only 121 MiB free; after ignored reproducible state/cache cleanup, a fresh retry applied migrations 00010030. Corrected focused proof passed 13 files / 84 tests; full bun run verify passed 54 files / 523 tests, TypeScript, and Vite assets/index-Bwbik46R.js. Docs/diff/count gates follow this entry.

2026-07-15 — Persisted Package billing and shared fulfillment ownership

  • Added migration 0030_persisted_package_billing.sql: immutable Package cycles use UNIQUE(user_id, period_start), unique request and wallet identities, fixed 500,000-cent/25-lead economics, Package-specific schema readiness, and completion guards whose explicit NOT NULL keys make any zero-row D1 batch roll back.
  • Added D1-backed GET /package, POST /package/start, and POST /package/cancel. Activation and each deterministic UTC anniversary spend promotional funds first, preserve one immutable debit split, clamp the original anchor to short-month last days, create no entitlement on payment_required, and keep cancellation effective at the current paid period end with no refund.
  • Wired Package renewal into the scheduled worker independently of the default-off auction paths. Renewal and cancellation contend on the same subscription status/current-period-end predicate, so overlap cannot both advance the subscription.
  • Added database-wide lead_fulfillment_claims ownership used by direct Market, Territory, and Package. The explicit Package delivery seam accepts trusted already-classified Hot/PPC supply, stays within the paid cycle and 25-lead quota, creates portfolio/stage/general delivery/Package attribution, and never increments budget_spent. Automatic selection, fabrication, and import remain outside this child.
  • Replaced localStorage Package state and Billing's optimistic wallet debit with typed server calls and explicit loading, active, cancellation-pending, and payment-required UI truth. The required UI polish and simplification passes ran directly because this lane prohibited subagents; the existing production screenshot was not recaptured because this branch is not deployed and the walkthrough now labels it source/local-test only.
  • P1 correction: every paid cycle now records one completion-guarded settlement before renewal or due cancellation can advance. The automatic credit is (25 - delivered_count) * $200; it reverses the unused original debit tail purchased-first and then promotional, writes one immutable package_shortfall wallet reference, and records a durable zero-credit outcome after all 25 deliveries. Concurrent/repeated settlement cannot double-credit. Client request keys and billing completions are scoped by authenticated user instead of globally.
  • P1 verification: fresh local bootstrap applied migrations 00010030; focused proof passed 8 files / 75 tests; full bun run verify passed 47 files / 508 tests, TypeScript, and Vite assets/index-DAahTaMR.js. Docs build and git diff --check passed.
  • Final response-loss recovery: Package start retains one browser idempotency key across ambiguous retries, refreshes D1 truth after a lost response, and preserves a concurrent cancel_at_period_end result. Terra/high reran the required sexy-then-simpler gate; focused Billing passed 10/10 and final bun run verify passed 47 files / 510 tests, TypeScript, and Vite assets/index-B9z8NYv_.js; docs build and diff hygiene passed.
  • Exact-head review rejected immutable head 29e4d7acb73f1ec1a89a0019c02aaee42f5a2518 for four P1s: due cancellation could lose to renewal and report plain active state; migration 0030 did not bridge recoverable pre-existing Territory debits; automatic fulfillment had no installed caller despite purchasable UI promises; and Billing could not restart a funded payment_required buyer. Sol also identified mutable idempotency replay semantics as P2.
  • The correction persists cancellation intent and reconciles both race orderings, including immediately crediting/canceling a successor that renewed first. Migration 0030 now bridges debited to shared claimed ownership and committed/allocated recovery to completed ownership with exact territory:<claim_token> fencing, while a NOT NULL preflight aborts unsupported or ownerless legacy state.
  • Migration 0030 creates package_fulfillment_state empty. GET reports fulfillmentReady=false; activation, renewal, explicit delivery, and Billing charging fail closed until the Admin CSV/routing child installs the actual caller and inserts the enabled row. Funded buyers can start a new immutable cycle from payment_required; old request replays retain their original 402/201 outcome regardless of later subscription/readiness state.
  • Correction verification: fresh bootstrap applied 00010030; focused upgrade/race/cross-channel/route/security/Billing proof passed 12 files / 103 tests. Terra/high then ran the mandatory make-it-sexy group followed by make-it-simpler directly on the corrected Package UI/API files; the dialog now traps forward/reverse focus, closes consistently, and returns focus to its opener. Focused Billing passed 11/11. The final corrected and polished tree passed 49 files / 517 tests, TypeScript, and Vite assets/index-7kTP1dMe.js; all touched TypeScript/TSX files remain at or below 400 lines.
  • Docs built 10 internal plus 2 client documents and the index; git diff --check passed. A root bun test attempt was discarded because it bypassed the configured Vitest/Node-SQLite runner. No remote service, push, deploy, PR, or screenshot recapture ran; corrections remain separate from the immutable rejected implementation commit.
  • Baseline before edits passed 46 files / 489 tests, TypeScript, and production build. Fresh local bootstrap applied migrations 00010030; final focused proof passed 8 files / 66 tests; full bun run verify passed 47 files / 499 tests, TypeScript, and Vite assets/index-Bnw2mWu_.js; docs build and git diff --check passed. Expected forced rollback/compensation stderr, the pre-existing duplicate SO_1 Territory key warning, and Vite's bundle-size advisory remain non-failing diagnostics. No commit, push, deployment, remote D1/Stripe access, or other remote mutation ran.
  • Next: Admin CSV/import integrity, then route only trusted classified Hot/PPC supply into the explicit Package delivery seam before exact-SHA staging acceptance.

2026-07-14 - Wallet subledger and exact-refund integrity child

  • Started from exact v60 master 5ae63047773a561da57df9c26d4832449a5b3c1d on codex/v60-wallet-refund-integrity. The resolved contract is promotional-first spending, no MVP promo expiry, and exact reversal of the original purchased/promotional debit split.
  • Added migration 0029_wallet_subledger_refund_integrity.sql. users.balance remains the public total, purchased plus promotional components must reconcile to it, and held balance must remain covered. Historical totals are preserved exactly as purchased/zero promotional because older provenance cannot be reconstructed; historical ledger rows receive conservative splits and are sealed immutable.
  • Classified new money at its trusted source: signup and the server-snapshotted verified Stripe funding bonus are promotional; verified Stripe principal and localhost-only fixture deposits are purchased. Checkout fails closed before provider work when the complete wallet schema marker is absent, and signed provider replay retains its existing unique economic fences.
  • Ported direct Market and Territory allocation to promotional-first component debits. Market claims the exact observed component snapshot so a concurrent Stripe credit makes the stale attempt retry instead of spending purchased funds ahead of promo. Territory persists a token-owned pending ledger/debit split, compensates only while unsealed, records durable commit completion, and seals the row before final allocation.
  • Bound each eligible refund request to exactly one proven Market/Territory debit. Foreign-key-safe parent-first creation is serialized by a partial unique pending-portfolio index. Approval permanently records one portfolio/source-debit outcome and restores the original split once; decline completion is constraint-backed. Unresolved historical provenance remains declineable but cannot mint funds.
  • Code-first rollout is fail-closed: registration, provider/local wallet funding, Market purchase, Territory entry, refund request, and Admin refund decision return retryable 503 wallet_schema_not_ready until the exact marker and every required table/column exist. Read-only Admin refund listing and Stripe Portal access remain available.
  • Remote preflight was read-only. Staging had zero invalid user/hold rows, unknown wallet types, duplicate economic references, duplicate approved/pending refunds, or in-flight Stripe sessions. Production predates migrations 00250028; its two repeated stripe reference groups are known legacy fixture groupings, not provider economic replay. Every query reported changed_db: false.
  • Fresh local bootstrap applied migrations 00010029. Real SQLite with foreign keys enabled proved all seeded historical rows sealed, UPDATE/DELETE rejected, parent-before-claim accepted, and a second pending refund rejected and rolled back. Sol's first immutable-head audit then reproduced a committed-before-seal Territory deletion window missed by Terra's initial approval. The narrowed trigger now permits compensation deletion only before durable commit completion; real-schema proof covers pending deletion, committed deletion rejection, the sole seal transition, and sealed UPDATE/DELETE rejection. Focused wallet/refund proof passed 50/50; final bun run verify passed 46 files / 489 tests, TypeScript, and the production Vite build; git diff --check passed.
  • Sol/medium completed the required walkthrough make-it-sexy pass, splitting dense wallet/refund proof into shorter fact-preserving bullets; the direct Terra/high make-it-simpler pass found no further safe compression. Docs build and file-scoped diff check passed. No app UI changed, so the existing Billing/Admin screenshots remain accurate and were not recaptured.
  • No remote D1 migration, Stripe mutation, deployment, commit, push, or PR publication ran during implementation. Next: exact-head Sol/Terra review, ready child PR with Zak requested, then persisted $5,000 Package billing.

2026-07-14 - Buyer-auction mutations parked for MVP

  • Started from exact clean base b1b870931916f6fa1b107246fcf7ea22fd985a64 on codex/v60-park-auction-mutations. The product decision is explicit: buyer auctions are post-MVP, so this slice parks their mutation reachability rather than repairing or broadening auction economics.
  • Added one exact-string AUCTIONS_ENABLED policy. Only true enables it; missing, false, TRUE, 1, whitespace, and other malformed values remain off. Disabled bid and buy-now POSTs return 410 { error: "feature_unavailable" } at the Worker boundary before browser/session auth, request parsing, D1, wallet, ledger, portfolio, or realtime work.
  • Closed every P0 alias from Terra's read-only plan: cron, exported settlement/restock helpers, Worker WebSocket dispatch, direct routeRealtime, and broadcastToRoom all fail closed before D1 or Durable Object access. /api/v1/health exposes only auctionsEnabled: boolean; no raw binding value is returned.
  • Preserved read-only auction GETs, auction/bid tables, Durable Object classes/bindings, realtime event code, archived A_MARKET_SENTINEL, direct Market purchase, and Territory allocation. No UI or migration changed, and no cleanup/deletion path was added.
  • Read-only production D1 preflight: 27 active, 3 discount, 2 ended-sold, and 1 archived sentinel auction; zero active/discount auctions have bids; two users have 21,500 held cents but neither is a leader on a current lot; 14 portfolios use the sentinel. The stale holds pre-exist and require separate reconciliation, not writes in this slice.
  • Read-only staging D1 preflight: one archived auction, zero active lots with bids, zero held balances, and zero sentinel portfolios, but lookup of A_MARKET_SENTINEL returned no row. Staging reset/provisioning must restore the sentinel before Market/Territory testing. Every production and staging query reported changed_db: false.
  • Operational gate: default-off can strand existing leader holds because bid/buy-now/settlement are all parked; re-enabling can make the next cron immediately settle overdue lots and charge held winners. Reconciliation of stale holds/lots/timestamps is a separate reviewed operator action; this slice performs no cleanup writes.
  • Evidence: frozen install and baseline full verify passed 43 files / 410 tests, TypeScript, and Vite. Final post-Terra gate, enabled-mode, realtime, Market-sentinel, and Territory-sentinel coverage passed 8 files / 98 tests; full verify passed 44 files / 442 tests, TypeScript, and Vite assets/index-COujzqxe.js. Docs build and diff check passed. Sol/medium completed the mandatory walkthrough make-it-sexy pass and corrected one stale wallet-status sentence; Terra/high completed make-it-simpler with no further edit. Expected forced rollback/compensation stderr, the pre-existing duplicate SO_1 test key, and the Vite bundle advisory remain non-failing diagnostics. No commit, push, PR, deploy, remote write, or secret mutation ran.
  • Next: complete the local closure gates and exact diff receipt. Before any staging acceptance run, rebuild/reset staging through the canonical migrations so A_MARKET_SENTINEL exists; before any eventual auction re-enable, audit and reconcile overdue lots and holds explicitly.

2026-07-14 - Atomic direct Market purchase child slice

  • Started from exact clean base f4c9a8ec8d3eb6e6b79207b680ea8b4ba7c1f88f on codex/v60-atomic-market-purchase; read PR #180 commit 47e4393 only as semantic prior art and did not cherry-pick or merge it.
  • Added migration 0028_atomic_market_purchases.sql: one immutable unique claim per direct-Market lead binds authenticated buyer, canonical acquisition/tier, ruled server price, portfolio, and delivery channel. A partial unique Market-ledger index adds a second durable double-charge fence.
  • Reworked POST /market/leads/:id/buy so request bodies cannot supply buyer/tier/price, canonical acquisition sets Cold $90 / Warm $150 / Hot $250, vertical/account/balance/budget/state are rechecked inside the claim, and one D1 batch owns sold state, wallet debit, ledger, portfolio/stage, and delivery. Same-buyer retries return the existing outcome; competing buyers receive 409.
  • Public Market list/count truth now matches charge truth: pending/unclassified, invalid stored-readiness-price, any auction-owned/history row, and non-open_market Territory-claim rows are excluded; returned marketPriceCents is derived from canonical acquisition. The same ownership fences are repeated in purchase preflight and the atomic claim. Terra/high caught that checking only active/discount auctions left an ended_sold cross-channel double-sale path because buy-now does not update leads.market_status; the corrected invariant rejects every auction row without rebuilding the parked auction product.
  • Read-only migration preflight against production D1 soldi found 11 historical Market ledger rows and 0 duplicate reference_id groups; staging D1 soldi-staging found 0 Market rows and 0 duplicates. Both queries reported changed_db: false, so the partial unique Market-ledger index has current-data deployment proof as well as fresh-schema proof.
  • Refreshed docs/walkthrough.html so the wallet release slide no longer calls atomic Market purchase unbuilt: it now labels the child implemented and fresh-local-D1 proven but not merged/deployed, and carries forward wallet/refund, Package, parked-auction, and exact-SHA staging gates.
  • Evidence: frozen install green; initial Market/security/rules suite 102/102; post-review cross-channel suite 42/42; fresh isolated local D1 applied migrations 00010028 and exposed the claim table plus both indexes; post-remediation bun run verify passed 43 files / 410 tests, TypeScript, and Vite assets/index-COujzqxe.js; docs build and git diff --check passed.
  • No UI, FHC, Package, refund, import, auction behavior, deploy, remote D1, Stripe, commit, push, or PR mutation. Next after verification: wallet purchased/promotional subledgers and exact refund integrity remain separate children.

2026-07-14 - PR #196 reconciled with live FHC main

  • Fast-forwarded the master worktree to exact remote PR #196 security head 408e801, whose GitHub CI passed app verify and FHC audit, then normally merged current origin/main 184a7a7 after PR #199/receipt PR #201.
  • Product, Worker, migration, FHC source, and asset trees merged without conflict. Resolved only BUILD_LOG.md, the implementation-note index, and walkthrough copy; both append-only histories remain intact.
  • Walkthrough resolution preserves all three truths: FHC is live under the resolved mixed model, Comps is post-MVP, and current Stripe test-mode transport is proven while PR #196 provider/CSRF hardening and the remaining atomic money/Package/staging gates are not deployed.
  • Zak received the complete C55-C64 copy disclosure and ledger link in short messages verified in the Messages database after three longer package writes truncated.
  • Merged-tree gates passed: app 41 files / 400 tests plus typecheck and Vite assets/index-COujzqxe.js; FHC 42 tests, 965 pages / 255 Spanish twins, recursive 966-HTML audit at 0 blockers / 0 warnings; docs build and diff check green.
  • No Soldi app deploy, remote D1 write, Stripe mutation, or DNS change occurred. Next: complete merged-tree gates, push PR #196, then cut atomic Market purchase as the next ready child PR.

2026-07-13 - Master train reconciled with main PR #161

  • Re-read ready PR #196 and all comment/review surfaces (none present), then PR #161's body and full Zak supersession chain. The governing instruction remains f8b192b / build v60: CHOOSE Cold/Warm/Hot, SUBSCRIBE to 25 delivered Hot leads for $5,000, and OWN through a tier-covering Territory bid; PR #193 is the real app.
  • Fetched exact origin/main d2d8173572c39d706fc3e03b45c8ce6cd0dd2cba and began a normal non-rebase merge into exact train head 8f57b8f3f012d7649bdd6c3ab20d6312a9dea49d. The train already contained f8b192b through e9017e6, so Git reported no conflicts and no product-content delta.
  • Retained the byte-identical v60 preview twins at SHA-256 fbe6ed23b8507617a910068f3c1c3e7ca1293af80ea67fcee1bc4e687938c58c plus every reviewed PR #197 Stripe and PR #198 acquisition/Territory migration, worker, API, test, and note. No app UI or preview file was hand-edited.
  • Verification on the reconciled tree: focused acquisition/Territory/Market/UI suites 202/202; disposable local D1 applied migrations 00010027 and exposed the funding/allocation tables plus unique Territory outcome indexes; full bun run verify 39 files / 381 tests, TypeScript, Vite assets/index-LfcA747C.js; docs build and diff check passed. Expected adversarial-test stderr, the existing duplicate SO_1 test key, and the Vite bundle advisory remain non-failing diagnostics.
  • Both-parent comparison found integration documentation as the only final-tree delta from the train parent. Relative to main, the retained product delta is the reviewed PR #197/#198 backend; both preview twins are unchanged against both parents.
  • No PR merge, deploy, remote D1/Stripe write, or external message. Next: execute PR #196's remaining economic and operational launch gates in focused planes.

2026-07-13 - PR #198 P1 rereview compensation ownership fix

  • Terra/high found a second-await race in the finalization error path: compensation published takeover-eligible finalizing, then an unguarded helper could refund/decrement after a new owner took over and debited.
  • Consolidated finalization compensation into one D1 batch. Cleanup, aggregate reversal, lead reset, standing-order weekly/spend reversal, wallet credit, and the final transition to retryable finalizing all require the same lead ID, claim token, and expected status. The claim remains non-takeover-eligible until wallet/order reversal is complete; the unguarded release helper was removed.
  • Added deterministic A/B scheduling: A fails finalization and compensates, B takes over/debits/allocates, then A resumes. B retains balance/budget 85000/15000, order count/spend 1/15000, and exactly one ledger/portfolio/delivery/counter outcome.
  • Evidence: focused Territory/Admin/ingest/rules 160/160, canonical acquisition 11/11, FHC payload 3/3; fresh disposable migrations 0001–0027 plus claim table/index query; full bun run verify 39 files / 381 tests, TypeScript, Vite assets/index-LfcA747C.js. Docs build and diff check are publication gates. The forced failure test emits its expected error; the duplicate SO_1 test key and bundle-size advisory are unchanged.
  • No deploy, remote D1/Stripe write, or secret access. Next: push PR #198 and request Terra/high rereview.

2026-07-13 - Marketplace v60 canonical acquisition plane

  • Added migration 0026_canonical_lead_acquisition.sql: raw leads.source remains campaign/manual provenance, while constrained leads.acquisition_source stores only cold, organic, ppc, or explicit pending. No source-string inference runs; only the 18 code-owned v60 fixture IDs are classified.
  • Made FHC/HMAC ingest pending-only and non-allocating. Authenticated Admin manual/review boundaries accept only the exact canonical enum, omission defaults pending, and campaign-like/near-miss values return 400 without writes.
  • Propagated raw and canonical attribution separately through Admin pending/supply-funnel, Market, and owned-lead APIs. Tier filters/counts use canonical acquisition only; pending rows have no tier and direct Market purchase returns 409 before any wallet/portfolio write.
  • Admin CSV import is not present on this launch train and was not imported from the stale integration branch. Market charging, territories, Package, refunds, deposit bonuses, and product UI were unchanged.
  • Evidence: local D1 migrations through 0026; local counts cold/organic/ppc 6/6/6 and historical pending 47; focused acquisition/worker suite 91/91; FHC payload suite 3/3; full bun run verify 38 files / 374 tests plus TypeScript and Vite assets/index-LfcA747C.js; bun run build:docs; git diff --check. Only the pre-existing duplicate SO_1 Territories test-key warning remained. No deploy or remote D1/Stripe write ran.
  • Published implementation commit a60ead9 in ready PR #198, targeting orchestrator/marketplace-v60-20260713/merge.
  • Next: land this focused PR, then implement atomic server-authoritative Market purchase as a separate plane.

2026-07-13 - PR #197 synced to Zak-audited launch train

  • Fetched and merged launch-train head e6ac7c1 into the Stripe-integrity branch after the full Zak PR/comment audit and territory-allocation terminology correction advanced the target.
  • Resolved BUILD_LOG.md, the implementation-note index, and marketplace-v60-mvp-buildout.md conflicts by preserving both histories: the newest Zak corpus audit remains intact and precedes the append-only Stripe P1 and initial implementation sessions.
  • Accepted the incoming ROADMAP and alignment-matrix corrections. The merge introduced no product-code edit; the staged delta from pre-merge PR #197 is documentation-only.
  • Evidence on the merged tree: focused Stripe/client suite 32/32; bun run verify 38 files / 371 tests plus TypeScript and Vite assets/index-B7oeNN0b.js; git diff --check clean. Only the pre-existing duplicate SO_1 Territories test-key warning remained. No deployment, remote D1 mutation, or Stripe write ran.

2026-07-13 - Zak v60 contract audit + first backend integrity plane

  • Read every recent Zak-authored PR body and all issue comments, reviews, inline comments, and current heads. The marketplace contract is PR #161's final v60 supersedes everything above comment plus merged PR #193; #160/#162/#168/#176–#179/#194 are FHC-only, and no hidden review thread changes the marketplace direction.
  • Corrected a dangerous terminology ambiguity: the buyer-facing Standing Orders/auto-buy product remains deleted, while territory allocation retains the legacy standing_orders persistence internally. Backend plans now say territory allocator rather than implying the dead product should return.
  • Kept Admin CSV import in the operational MVP sequence. It is separate from the parked buyer + Add lead affordance and is required to load saleable inventory.
  • PR #197 selectively ports Stripe wallet-funding intent/economic replay integrity onto the launch train. Its first adversarial review caught an ambiguous-retry defect; head 631fecc reuses an amount-scoped implicit request key after failure, rotates after valid success or amount change, and protects newer state from late responses.
  • Evidence at PR #197 head 631fecc: 32 focused Stripe/client tests; 38 files / 371 tests plus TypeScript and Vite build; local migrations through 0025; git diff --check clean. No UI, remote D1, Stripe account, or deployment changed.
  • Next: current-head adversarial merge verdict, then canonical fail-closed acquisition, atomic Market purchase, territory enforcement, deposit/promo subledger, refunds, Admin CSV import, and persisted Package behavior as focused PRs into the master launch train.

2026-07-13 - PR #197 P1: amount-scoped Checkout retry key

  • Adversarial review found that Billing's one-argument walletCheckout(amountCents) call generated a fresh UUID per attempt. After an ambiguous first response, a second click could therefore create a second payable hosted Checkout Session despite the server-side intent controls.
  • Moved implicit retry-key lifecycle into the API client without touching Billing.tsx or any visual/UI file: a failed or ambiguous call retains one key for that amount, a valid session response clears it, and an intentional amount change replaces it. Cleanup compares both amount and key so a late older success cannot clear newer pending state.
  • Explicit requestId behavior is unchanged and bypasses implicit state.
  • Evidence: focused Stripe/client suite 32/32; final bun run verify passed 38 files / 371 tests, TypeScript, and Vite assets/index-B7oeNN0b.js; git diff --check clean. Only the pre-existing duplicate SO_1 Territories test-key warning remained. No deployment, remote D1 mutation, or Stripe write ran.

2026-07-13 - Marketplace v60 Stripe funding integrity

  • Semantically replayed only the Stripe economic-integrity seam from PR #187 (fd39972, f6c2950) and PR #181 (3083fc0) onto launch-train base d5108de; the old integration branch was not merged and its Market, refund, Admin CSV, Package, and UI work was excluded.
  • Added local migration 0025_stripe_economic_payment_integrity.sql: each wallet-funding request now binds user, integer-cent amount, USD currency, expected test/live mode, caller retry key, provider idempotency key, hosted Checkout Session, and PaymentIntent to one server-owned intent.
  • Hosted Stripe Checkout and Portal behavior remains intact. Checkout requests carry a stable Stripe Idempotency-Key; caller retries reuse the stored session, while reuse with changed economics fails with 409.
  • Signed paid-Checkout webhooks now match stored economics and atomically write the event claim, unique economic claim, PaymentIntent binding, wallet balance, and ledger row. Same-event replay, distinct-event Checkout/PaymentIntent replay, and persistence-failure retry cannot double-credit.
  • Evidence: focused Stripe/client suite 29/29; fresh local-only D1 migrations 0001–0025 applied successfully; final bun run verify passed 38 files / 368 tests, TypeScript, and Vite assets/index-DnXY520a.js; git diff --check clean. Only the pre-existing duplicate SO_1 Territories test-key warning remained. No remote D1/Stripe write or deployment ran.

2026-07-16 — FHC fabricated city-data review follow-up verification (pushed branch; not deployed)

  • The hostile-review repair passed focused negative proof: five independently fixed CitySchema unknown-key payloads reject, fixed source/claim sentinels pass, and legitimate rendered buyer: disclosure copy is explicitly allowed by the rendered-claim scanner. This separates the strict source boundary from generated-copy scanning without weakening either.
  • Evidence: FHC bun test 456/456 across 10 files; clean build 965 generated pages / 255 Spanish twins; independent root audit rerun took ~60.7 seconds and passed 630 pages / 966 recursive copy-policy HTML / 102 thin-gate diffs with 0 blockers and 0 warnings; provenance --check 103 rows / 0 disagreements; offline links 8/8 cached URLs healthy; root verify 37 files / 354 tests + production build; docs build 10 internal + 2 client docs; git diff --check passed.
  • Two clean post-repair manifests have the same 1,191-file aggregate SHA-256 aaab2b6b437b6f6941c2ef7ac0732ca9ffab1b2e012641aa1a55c4d9870fd51c as the pre-removal receipt. Public FHC output remains byte-identical. No PR, merge, deployment, or Zak message was performed.

2026-07-16 — FHC fabricated city-data review follow-up (pushed branch; not deployed)

  • Hostile review blocked pushed codex/fhc-remove-dead-fabricated-city-data head 5c078caf on two integrity gaps, not public copy: CitySchema silently stripped unknown keys, and the broad guard/test/audit marker catalogue could self-mask if edited with a restored payload.
  • The narrow follow-up makes CitySchema strict and adds five fixed negative payload cases (buyer, socialProofCount, reviewCount, testimonials, toastActivities). It also adds fixed, local audit/test sentinels for those five keys and representative fabricated persona, reviewer, volume, activity, and closing claims, independent of the broad catalogue. FHC_REVIEW_COUNTS remains untouched.
  • The source-only branch was already pushed at 5c078caf; this follow-up remains un-deployed and does not alter Zak's restored fhc-10 plan. Final follow-up commit/push and clean-output evidence are recorded in docs/implementation-notes/fhc-dead-fabrication-removal.md.

2026-07-16 — FHC current-state correction

  • Current shipped truth supersedes stale walkthrough/current-status language: PR #214 is merged and live as 2f5e618 on Cloudflare FHC Worker version ad00e313-b824-4bd0-9883-b09b8f85f3fb at 100%. #216 and #217 are merged to main; Always Use HTTPS and apex/www redirects were verified.
  • The new codex/fhc-remove-dead-fabricated-city-data branch is a source-only cleanup from the #217 merge. It is not deployed and carries zero public FHC output delta. This correction does not rewrite historical entries below or alter Zak's restored fhc-10 plan.

2026-07-16 — FHC dead fabricated city-data removal (local branch; not deployed)

  • Created codex/fhc-remove-dead-fabricated-city-data in the isolated /private/tmp/soldi-fhc-dead-fabrication-removal worktree from the exact PR #217 merge origin/main 1d1af89cb73d21d8f9ad572a155c7da59b979d60; the earlier FHC reconciliation worktree was not touched.
  • Removed the dormant fabricated social-proof payload at the CityData schema/data/generator boundary: counts, buyer persona/quote/track-record fields, curated testimonials, toast activities, their two hand-authored fixtures, and the now-dead persona/avatar/testimonial/toast generator helpers. Deleted data/testimonials-curated.ts rather than leaving disconnected fabricated material in the tree. The approved mixed direct-purchase/partner copy model and the separate real FHC_REVIEW_COUNTS injection remain unchanged.
  • Added a source-and-fresh-dist audit gate plus unit regression coverage for all retired fields, 15 buyer personas, 75 curated reviewer names, fabricated volume/dollar values, and concrete activity claims. It fails if a boundary field, the curated payload module, or a known false claim returns to source or generated HTML.
  • Pre- and post-change clean full-dist/ manifests are byte-identical: 1,191 files, aggregate SHA-256 aaab2b6b437b6f6941c2ef7ac0732ca9ffab1b2e012641aa1a55c4d9870fd51c. There is no FHC generated-copy or asset delta. Final verification and push evidence are recorded in docs/implementation-notes/fhc-dead-fabrication-removal.md.
  • Next: review the committed local branch and open a PR only with owner approval; no PR, merge, deployment, or external message was performed in this slice.

2026-07-16 — FHC post-#214 docs and CI follow-up

  • Zak approved #214's implementation substance after comparing it with his branch, then identified two real follow-ups: the required freshness/superseded-claims documentation from dce35f8 was absent, and the path-filtered FHC audit when changed job ran build/audit without executing the regression suite.
  • Cherry-picked Zak-authored dce35f8, preserving round3-freshness-scope.md and superseded-claims.md with a dated current-status addendum. The unrelated 401-line fhc-10-editorial-plan.md remains in exact commit history but is not published as current truth because its connector-only and zero-closings/pre-launch assumptions require a future FHC-10 rebase. Added bun test to the existing FHC CI job before build/audit.
  • Reproduced the test-count discrepancy instead of guessing. Exact dce35f8 passes 526 tests across six files; exact merged #214 passes 447 across eight. The four new integrity test files are byte-identical and contribute the same 400 tests. The difference is the policy model: Zak's stale connector-only copy-policy.test.ts has 123 tests, while current main's approved mixed direct-purchase/partner version has 36, a deliberate reduction of 87; current main adds five heading and three embed tests. Therefore 526 - 87 + 8 = 447.
  • Accepted Zak's wording correction: the conditional-offer scanner is a regression tripwire for enumerated constructions and disclaimers, not a semantic guarantee against arbitrary novel phrasing. Corrected the historical parser spec and internal source comments to the approved mixed direct-purchase/partner model; no public copy changed.
  • Next: exact-head full verification and hostile review, ready follow-up PR with Zak requested, then merge after CI. No provider setting, Worker code, generated page, or live copy changes in this slice.

2026-07-15 - Fair Home Cash heading scanner hardening (local integration branch; not deployed)

  • Review found that the initial heading scanner's paired-tag regex did not recognize legal whitespace in </script >, </style >, or </template >; fake headings in those inert regions could therefore distort the result. Replaced it with a token/state parser that recognizes whitespace-close forms, keeps script/style raw text opaque, and handles nested template/script/style regions.
  • Added two adversarial fixtures: exact whitespace-closing forms prove inert fake headings are ignored, while a nested inert region followed by a visible h3 proves a real h1 → h3 skip cannot be bypassed. The scanner unit suite now has 5 cases and the full FHC suite is 447 tests.
  • Deleted the ignored generated sites/fhc-pages/dist/ directory and rebuilt from the current source before audit. Fresh output: 965 generated pages / 255 Spanish twins, 966 recursive HTML files, and 0 skipped heading levels under the hardened scanner. No copy or CSS source changed in this corrective commit.
  • Evidence: FHC bun test 447/447; FHC audit passed; provenance --check 103 compared rows / 0 disagreements; offline link health 8 cached URLs / 0 failures; root bun run verify passed typecheck, 37 files / 354 tests, and production build; docs build passed 10 internal + 2 client docs; git diff --check passed. The follow-up was committed and pushed without opening a PR. No deployment was requested or performed.

2026-07-15 - Fair Home Cash heading-order review reversal (local integration branch; not deployed)

  • An independent exact-SHA review found no P0/P1 issues but reopened the previously pushed FHC reconciliation for a P2: #208's accessibility claim lacked a generated-corpus heading-order gate. The review reported 94 affected pages in the 966-page corpus. A deterministic pre-fix scan of 74e7383 found 93 affected pages: 51 calculator h1 → h3 skips and 42 static h2 → h4 skips; no nested language twin failed. The count discrepancy is recorded rather than concealed.
  • Added heading-order.ts plus unit coverage and made audit.ts scan every recursively collected built HTML file. It ignores only non-rendered scripts, styles, comments, and inert templates; there are no page or component exemptions. Any upward jump larger than one level is a launch blocker.
  • Repaired the 50 state calculator template outputs, the Illinois calculator, and all 42 affected static sources by changing heading elements and their matching CSS selectors together. Visual CSS and visible copy are unchanged. The rebuilt 966-file corpus has 0 skipped heading levels.
  • Evidence: FHC bun test 445/445; FHC build 965 pages / 255 Spanish twins; recursive heading probe 966 HTML / 0 skips; FHC audit passed; provenance --check passed 103 compared rows / 0 disagreements; offline link health passed 8 cached URLs / 0 failures. Root bun run verify passed typecheck, 37 files / 354 tests, and production build; docs build passed 10 internal + 2 client docs; git diff --check passed. Commit and push remain in this session. No deployment or PR was requested or performed.

2026-07-15 - Fair Home Cash Zak PR reconciliation (local integration branch; not deployed)

  • Created integrate/fhc-zak-reconcile from exact origin/main 184a7a7f0f04b9dd6d54cf13301530eb2b662444; no stale FHC branch was merged as-shaped. The provenance audit read every body, commit, issue comment, inline comment, and review for Zak PRs #194, #199, #208, #209, and #211. All five had zero submitted GitHub issue comments, review comments, and reviews at inspection time.
  • Kept the current owner-approved mixed model from #199 and the 2026-07-16 consolidated handoff: Fair Home Cash may directly buy qualifying houses and may work with partners; offer outcomes remain conditional. #194/#199 are already ancestors of the requested base. #208/#209/#211 forked before that correction, so only non-conflicting work was selectively integrated.
  • Preserved Zak-authored citation/source-link, conditional-offer, monetary-rounding, provenance, and link-health commits where safely reusable. Rebuilt #208's CSP/accessibility work on current main: ordinary responses now deny framing while the explicit calculator embeds retain their deliberate framing exception. Corrected Illinois market citations and the stale 50-day median to the cited May 2026 27-day figure; added the missing conditional-policy word counter exposed by the imported test suite.
  • #209's source-map concept was ported as a current docs/content/SOURCE_OF_TRUTH.md; its stale connector-only model, ungated-offer assertion, inherited code, local Desktop paths, and stale launch claims were not carried forward. The full copy/provenance delta and conflict record are in docs/implementation-notes/fhc-zak-integration.md.
  • Local evidence: FHC bun test passed 442 tests; bun run build generated 965 pages / 255 Spanish twins with 258 provenance facts (153 sourced, 105 derived) and 103 independently compared values; bun run audit passed. Root bun run verify passed typecheck, 37 test files / 354 tests, and production build; bun run build:docs built 10 internal + 2 client docs; git diff --check passed. The integration branch was committed and pushed without opening a PR; no deployment was requested or performed.

2026-07-14 - PR #199 merged and Fair Home Cash best-site wave live

  • Merged Zak's PR #199 to main as 8abfe6bb98bf554fe10ce3246dd01fe901d0a84e after immutable-head Sol approval and GitHub CI. The release preserves Zak's 43ca26f best-site wave and records all later owner/reviewer copy changes as C55-C64/A12-A14.
  • Deployed the exact merged tree to fhc-pages; Worker version 8b16585d-dd35-4f26-acc4-fb26b7f3a488 is active. Rollback target is 6f180e61-f7bc-4eaa-98e4-8a5605e041e3.
  • Live proof passed: www 301 preserves path/query at apex; representative FAQ, selling-cost report, Chicago neighborhood, EN/ES divorce, and PNG favicon routes return 200; /offer serves the final conditional reassurance.
  • Live framing policy passed: ordinary pages and ordinary calculator views are SAMEORIGIN; only generated calculator ?embed=1 and the dedicated Illinois embed allow frame-ancestors *.
  • Refreshed the walkthrough truth surface: Comps is explicitly post-MVP, the FHC mixed model and live receipt replace the obsolete unresolved-model warning, and Stripe's proven test-mode transport is separated from the still-open atomic-wallet/refund/Package semantics. Sol/medium make-it-sexy and Terra/high make-it-simpler reviews passed; only buyer floor -> buyer marketplace was additionally changed.
  • Wrangler uploaded 1,159 changed assets and activated the version, then exited 1 on the redundant custom-domain route update because the current token lacks Zone Workers Routes permission (Cloudflare code 10000). Deployment-list and hosted probes prove activation; no DNS or route mutation was needed.
  • Next: send Zak the explicit C55-C64 copy/live receipt, then continue the v60 master train with atomic Market purchase, exact refund integrity, Admin CSV import, wallet subledgers, persisted Package billing, and staging adversarial QA. Comps remains outside the MVP.

2026-07-14 - PR #199 Zak exact-head release reconciliation (not deployed)

  • Cameron resolved the engineering identity premise: Fair Home Cash may directly buy some houses while other transactions may use partners, so Zak's first-person we buy houses voice is not inherently dishonest. The team will not repeat the obsolete blanket non-buyer objection.
  • Reconciled Zak's three post-R6 commits at exact PR head 8eba975: closing-cost hero/CTA/number formatting (0068beba), market overlay and ballpark formatting (c8628a9b), and the full schema/meta/wizard/EN/ES buyer-network-language removal (8eba9756). No public wording was changed by Codex in this pass.
  • Expanded the durable copy ledger from stale C01-C40/A01-A10 to C01-C49/A01-A11, explicitly separating Codex's earlier reconciliation from Zak's latest public changes and audit expansion.
  • Evidence at 8eba975: FHC 126/126 tests; build 940 generated pages / 255 Spanish twins; audit 0 blockers / 0 warnings across 941 recursive HTML; root verify 37 files / 354 tests plus production build; git diff --check clean. Independent tmx Sol/medium and Terra/high desktop/mobile exact-head reviews are in flight.
  • No merge or deploy has occurred. Zak received a verified acknowledgment naming the exact head and promising the ledger plus live proof after deployment.

2026-07-14 - PR #199 R6 bounded classifier correction (not deployed)

  • Corrected Terra's exact 14-case matrix: six explicit EN/ES negations now allow, while eight acquire/determiner/joint-subject direct-buyer claims block on disclosure routes.
  • Consolidated direct principal-purchase matching through the bounded classifier so negation is evaluated once; retained seller-to-FHC grammar separately. Added n't/cannot, tampoco/jamás, English acquire forms, my/our/any, Spanish mi/mis, and joint-subject handling that still allows independent partners as the actual purchaser.
  • Added the 14 exact cases plus seven close controls across visible/JSON-LD/meta. Rebuilt disclosures stayed clean, so public copy remains exactly C01-C40 and enforcement/test wording advances only to A10.
  • Evidence: 123/123 focused policy cases; FHC 126/126 total tests; build 940 generated pages / 255 Spanish twins; audit 0 blockers / 0 warnings across 941 HTML; independent exact matrix 8/8 blockers and 6/6 allowances in all three layers; 3/3 close blockers, 4/4 close allowances, and 11/11 non-disclosure boundaries; root verify 37 files / 354 tests plus production build.
  • No public page, form, consent, /api/offer-request, ingest, nurture, secret, or Wrangler behavior changed. No deploy, merge, text/contact, or subagent use occurred.

2026-07-13 - PR #199 R5 disclosure purchase-claim classifier (not deployed)

  • Terra's R4 release rereview confirmed every earlier attack and gate, then proved seven natural disclosure-only bypasses across English about/ready/looking/poised purchase intent and Spanish recent/near-future word order.
  • Replaced the enumerated intent/periphrastic regex with a bounded, readable subject -> purchase verb -> determined seller-property classifier. It permits ordinary tense, intent, and adverb phrases while rejecting negation, independent actors, editorial explanation, and request-through-FHC bridges; invocation remains limited to the four disclosure routes.
  • Added all seven Terra literals verbatim across visible/JSON-LD/meta, eleven close future/recent/adverbial/comparison EN/ES attacks, and eight neutral boundary controls. The rebuilt disclosure corpus stayed clean, so public copy remains exactly C01-C40 and enforcement/test wording advances only to A09.
  • Evidence: 102/102 focused policy cases; FHC 105/105 total tests; build 940 generated pages / 255 Spanish twins; independent 62/62 attacks across all three layers, 20/20 neutral allowances, and 62/62 non-disclosure boundaries; inventory 941 HTML / 2,755 description tags / 952 JSON-LD blocks; audit 0 blockers / 0 warnings; root verify 37 files / 354 tests plus production build. The inherited duplicate SO_1 key and Vite chunk-size warnings remain non-blocking.
  • No public page, form, consent, /api/offer-request, ingest, nurture, secret, or Wrangler behavior changed. No deploy, merge, text/contact, or subagent use occurred.

2026-07-13 - PR #199 R4 disclosure intent/periphrastic repair (not deployed)

  • Terra's release review confirmed every prior P1 closure and gate, then found four disclosure-only direct-principal gaps: first-person/named going to buy, named purchase intent, and named-FHC Spanish acaba de comprar.
  • Added a separate, seller-specific disclosure matcher for English going/planning/plan/intend/expect/aim buy/purchase forms and named/first-person-plural Spanish recent-purchase forms. Generic industry copy, independent-buyer copy, offer math, request-through-FHC, and non-disclosure routes remain explicitly preserved.
  • Added four exact R4 fixtures across visible/JSON-LD/meta, fourteen close EN/ES blockers, and four neutral controls. All authored and built disclosures stayed clean, so public copy remains exactly C01-C40 and enforcement/test wording advances only to A08.
  • Evidence: 76/76 focused policy cases; FHC 79/79 total tests; build 940 generated pages / 255 Spanish twins; independent inventory 941 HTML / 2,755 description tags / 952 JSON-LD blocks; audit 0 blockers / 0 warnings; root verify 37 files / 354 tests plus production build. Inherited duplicate SO_1 key and Vite chunk-size warnings remain non-blocking.
  • No public page, form, consent, /api/offer-request, ingest, nurture, secret, or Wrangler behavior changed. No deploy, merge, text/contact, or subagent use occurred.

2026-07-13 - PR #199 final bounded disclosure-grammar hardening (not deployed)

  • Terra's final rereview confirmed the prior public-copy reconciliation, FAQ/JSON-LD parity, recursive artifact counts, and audit, then found five direct disclosure-only grammar bypasses: We buy your house, We purchase your property, named-FHC future purchase, and two ordinary Spanish purchase/sale forms.
  • Extended only the disclosure-route strict matcher with seller-specific buy/purchase auxiliary, contraction, tense, progressive, indirect-object, and Spanish person/conjugation forms. Generic we buy houses, neutral offer-math/request language, and independent-buyer EN/ES examples remain explicitly allowed.
  • Added Terra's five attacks verbatim, ten close grammar blockers, four new neutral allowances, and authored-source regressions for About, Privacy, Terms, and legitimacy. No rebuilt disclosure blocker appeared, so public copy remains exactly C01-C40; enforcement/test wording advances only to A07.
  • Evidence: 54/54 focused policy cases; FHC 57/57 total tests; build 940 generated pages / 255 Spanish twins; independent inventory 941 HTML / 2,755 description tags / 952 JSON-LD blocks; audit 0 blockers / 0 warnings; root verify 37 files / 354 tests plus production build. Inherited duplicate SO_1 key and Vite chunk-size warnings remain non-blocking.
  • No public page, form, consent, /api/offer-request, ingest, nurture, secret, or Wrangler behavior changed. No deploy, merge, text, or subagent use occurred.

2026-07-13 - PR #199 second rereview: legitimacy disclosure identity repair (not deployed)

  • Reconciled six authored occurrences on /is-fair-home-cash-legit: the visible body/FAQ and FAQPage JSON-LD now describe offers as requested through Fair Home Cash or received by the seller, rather than our written offer, our offers, sell to us, or an offer from Fair Home Cash.
  • Hardened the shared copy policy with a disclosure-aware direct-principal family covering the reported EN forms plus reasonable EN/ES sale-to-FHC, named-buyer, and first-party-offer equivalents in visible, JSON-LD, and meta/OG layers. Connector disclosures remain allowed; neutral offer-math, requested-offer, and seller-received-offer wording has explicit allowance coverage.
  • Verification: FHC bun test 35/35 (32 policy + 3 ingest), build 940 generated pages / 255 Spanish twins, independent artifact inventory 941 HTML / 2,755 description tags / 952 JSON-LD blocks, audit 0 blockers / 0 warnings across all 941 HTML, and root bun run verify 37 files / 354 tests plus production build. Root verify retained the unrelated duplicate SO_1 React-key warning and Vite chunk-size warning.
  • Durable Zak handoff now contains C01-C40 public copy deltas and A01-A06 audit/test wording at docs/implementation-notes/fhc-copy-identity-audit-ledger.md; operator twin remains /tmp/soldi-v60-20260713-pr199-copy-delta.md.
  • No lead form, consent, /api/offer-request, ingest, nurture, secret, or Soldi-firewall behavior changed. No deploy, merge, or text was performed; PR rereview and any deployment remain root-owned.

2026-07-12 - Marketplace v51 source-priced money foundation (local only)

  • Started feat/marketplace-v51-foundation in an isolated worktree at immutable base 6a21f4a; the concurrent feat/fhc-seo-wave3 worktree and sites/fhc-pages/ were not touched.
  • Added one shared integer-cent marketplace rules module: strict cold/organic/ppc classification, $90/$150/$250 flat pricing, Cold+Warm-only bulk tiers, territory bid-versus-bucket eligibility, package shortfall returns, deposit minimum/bonuses, and budget new-spend versus prepaid-fulfillment behavior.
  • Removed the unused frontend freshness/quality variable-pricing formula and replaced its facade with the locked shared rules.
  • Review caught and prevented unsafe partial integration: FHC currently persists raw page/campaign slugs in leads.source, so strict organic|ppc|cold filtering would hide valid leads and cannot truthfully distinguish paid versus organic. The temporary Open Market/UI wiring was reverted before closeout.
  • Evidence: baseline bun run verify 264/264; all 24 local D1 migrations; final bun run verify 34 files / 331 tests plus typecheck/build after the review-driven revert; git diff --check clean.
  • Deliberately deferred: define/migrate canonical acquisition attribution, then wire ingest, Admin approval, Open Market, and territory allocation together while removing price bands/overrides/discounts and Standing Order auto-buy. No commit, push, PR, merge, or deploy in this slice.

2026-07-10 - FHC deploy: EHO official mark (PR #165) + export hardening (PR #164) live

  • Merged PR #165 (official HUD Equal Housing Opportunity mark in all 9 footer sources + checkEhoMark audit hard-gate; branch also carried main's three pending app commits — nav blob fix, PR-#161 port, copy edits). Gates before merge: bun run verify 264/264 tests, build 540 pages, audit LAUNCH READY.
  • Deployed fhc-pages (version 556a8ca1, 100%): live footer serves the EHO mark; /api/export/customer-match now 401s both unauthenticated AND the old ?key= form — Bearer header required (PR #164's change is now live). Known benign routes-attach auth error on deploy; worker activated regardless.
  • Zak texted the go-live + the new curl auth form.
  • Later same day: merged PR #162 (ultra-QA — IL calc favicon/logo + lead-loss, gclid coverage, ES exit/thank-you, API hardening: nosniff on json(), 256KB body guard, KV try/catch). Zak's AI had re-synced it with main; verified the Bearer-only export and EHO audit gate survived. Gates green (540 pages, audit 0 blockers, 264 tests). Deployed (version 1bb1fba9 — note: first deploy attempt built from a stale local main missing #162, caught and redeployed). Live-verified: calc favicon=1, home gclid=2, nosniff header on export 401. Queued: Search Console TXT verification (CF token lacks DNS scope — dashboard paste needed), sitemap submit, GBP setup (blocked on John).
  • Evening: Google Search Console verification shipped (PR #166) — verification HTML file (worker serves the exact .html path with 200; the assets layer 307s *.html to extensionless) + google-site-verification meta tag on all templated pages. Deployed; GSC now shows VERIFIED OWNER on the https://fairhomecash.com/ URL-prefix property. Discovered the property already had sitemap.xml submitted (Jun 26, Success, 536 discovered) and 330 pages indexed — indexing was already live. Users: camolechowski + FHC Support. Remaining: favicon-in-SERP watch item (data-URI icon may need a hosted /favicon.png), GBP verification blocked on John's entity docs.
  • Night: Cam's SERP screenshot confirmed the generic-globe favicon → shipped hosted /favicon.svg linked from all 540 pages + embed page (was data-URI, which Google ignores); deployed and live-verified (200 + link on home). Tracking ground truth corrected: GA4 G-3553MET586 was ALREADY the build default and receiving traffic — the audit placeholder warnings are Meta pixel only. Meta pixel/dataset remains the single missing ID, blocked on Meta Business login + suspected restriction. State documented in sites/fhc-pages/CLAUDE.md (tracking & search section), internal ADS-ACCOUNTS.md, and agent memory.

2026-07-09 - FHC /offer wizard hotfix (post-PR-#160 review)

  • Multi-agent review of PR #160 (already merged + deployed) surfaced two live funnel bugs on /offer: Enter in a step-1 field implicitly submitted the form and validated the hidden step-2 inputs (silent dead-end, no feedback), and the wizard emitted minor-repairs/2-3-months where every state-page wizard emits light-repairs/60-days — forking the Gold-Tier taxonomy by landing page. Fixed both (keydown guard advances the wizard; values aligned)
    • post-change-polish pass. Verified: build 540 pages, audit 0 blockers, wizard driven in Chrome against built dist (blocked-with-errors + advance paths both green). Queued from review, non-blocking: Customer Match export KV scan won't survive ~1000+ leads (sequential gets, subrequest cap); EXPORT_KEY secret turned out to already be set — endpoints are live.
  • Follow-up (same day): Customer Match export hardened — per-lead KV gets batched 50 at a time via Promise.all (was one sequential round-trip per lead), email/phone hashes parallelized, and auth moved from ?key= query param (leaked EXPORT_KEY into access logs) to Bearer header, matching /api/deal-close. Verified against wrangler dev: 401 without auth AND with the old query param, 3 seeded leads export a CSV whose hashes byte-match locally computed SHA-256 of the normalized email/+1-phone. Still one subrequest per lead — a ?since= cursor or rolling snapshot is the real fix past ~1000 leads. Deployed 2026-07-10 with PR #165.

2026-07-08 - Ads-launch package on fhc-ops + deck refresh + polish commit

  • /ads-launch/ (new, fhc-ops): the full launch checklist for both brands — Abdullah doc list (entity docs, EIN, proof of address, gov ID, payment instruments, GBP-viable address), state-of-play table, minimum / job-well-done / OCD tiers per brand-platform with owner tags, blast-isolation rule (no shared MCC/BM across FHC↔EF), and the MCP automation path (Meta official MCP turnkey; Google Ads MCP gated on Basic-Access developer token — apply early). Fed by 3 Exa research lanes (Google, Meta, MCPs).
  • /client-onboarding/ (new, fhc-ops, fable-authored): repeatable new-client walkthrough — shared intake phase + Track A (paid ads) + Track B (organic engine at scale), 52 steps each tagged auto/assisted/human. Scorecard: 20 auto / 19 assisted / 13 human → 75% agent-touchable; productization shortlist included.
  • Stale-state fixes: /fhc-ads-accounts/ updated — FB page + FHC ad account + pixel now exist under FHC's own Business account (cleaner than the planned Velli-BM account); hub index gained cards for both new pages.
  • Polish: two post-change-polish runs on all touched ops-fhc pages (scroll reveals, card spotlights, interactive checkboxes, dead-CSS pruning); app gates stayed green (264 tests, index-BneVUYIn.js). Earlier app polish pass committed (20125b7).
  • Deck/docs: walkthrough gained a setup-quiz slide + segmented-Market rewrite with fresh live shots; ROADMAP marks segmentation/quiz/nav DONE (0b606d9).

2026-07-08 - Zak's PR #160 merged + live: FHC ads-launch polish

  • Zak's feat/fhc-ads-launch-polish reviewed, conflict-resolved, merged (e980cc3), deployed. His branch predated main's mobile/i18n/meta/Ads-tag passes → 12 conflicts across 9 files. Union resolutions: kept main's display=optional fonts + standardized 44px header logo + ES lang-toggle; took his unified 24px favicon, header phone link, and 2-step offer wizard.
  • What his PR ships: 2-step /offer wizard with Gold-Tier fields (condition, timeline, occupancy, price expectation), auth-gated /api/export/customer-match (SHA-256-hashed Email,Phone CSV for Ads/Meta audiences) + /api/deal-close offline-conversion capture (both fail-closed on EXPORT_KEY), lead-store fail-loud when KV missing, Terms rewritten to pure lead-gen entity language (attorney-brief aligned), Fraunces brand font, exit-form consent validation, ES translations. During resolution I extended his new wizard fields into the ES layer (data-es on labels/options, lang-aware step labels) and de-duplicated the merged fullname block.
  • Proof: build 540 / audit LAUNCH READY / 3 worker tests green / AW+GA4 coverage 536/536 intact. Live: wizard blocks empty Continue, advances filled, ES toggle translates new fields, zero console errors; /terms serves the new language; export endpoint 401s on bad key.
  • Needs Cam: wrangler secret put EXPORT_KEY --config sites/fhc-pages/wrangler.jsonc (from repo root) before the Customer Match export / deal-close endpoints are usable.

2026-07-07 - Zak's #147 mockup port DEPLOYED to app.soldi.cc

  • The three merged port lanes (PRs #157/#158/#159) were sitting on main undeployed — Cam (rightly) flagged the live Market page unchanged. Root cause: I finished the merge + local QA, then context-switched to the ops split without running the deploy endgame.
  • Shipped: migration 0024_buyer_segmentation.sql applied to remote D1 (5 commands ✅), bun run deploy:app after a green gate (33 files / 264 tests, index-Dpe-t3MH.js).
  • Live proof: guest /market serves the investor view — SOURCE control (Inbound 10 / Cold-call 4), situation tabs, per-lead vert/source/sourceBucket, zero listing-lead leaks, masked addresses, consolidated nav (Reports/palette gone). First curl showed the old bundle: CDN-cached index.html, cache-busted fetch = new hash.
  • Still owed: walkthrough deck + shots refresh, ROADMAP touch, polish pass on merged files.

2026-07-07 - FHC Google Ads base tag live site-wide (AW-18306794294)

  • Cam created the FHC Google Ads account under the new Fair Home Cash Workspace (AJ/Google-assisted setup). The base tag needed deploying on fairhomecash.com.
  • Wiring: FHC_GOOGLE_ADS_ID (documented in analytics.env.example but never consumed) now flows through build.ts → the analytics.eta partial (city/state/homepage), the three inline-gtag templates (situation, IL-situation, state calculators), and the static-page copy loop — one extra gtag('config','AW-…') on the already-loaded gtag.js, under the existing Consent Mode v2 defaults. Live ID is the build fallback; env overrides.
  • Proof: build 540 pages, audit LAUNCH READY — no blockers, dist coverage GA4 536 / AW 536 / gap 0; deployed (worker upload green, known benign route-attach 401) and live-verified on /, /thank-you, /sell-my-house-fast-chicago, /sell-house-during-divorce-illinois, /illinois-foreclosure-deadline-calculator.
  • Queued next: GA4 property move (personal → Workspace via GA "Move property" — ID stays G-3553MET586, zero site changes), Ads↔GA4 link, import estimator/lead-form conversions. Plan of record: fhc-ops/fhc-ads-accounts/.

2026-07-07 - Zak mockup port lane B2: nav simplified, Refunds merged, Billing compacted

  • Branch-local mockup-port slice implemented on port/nav-simplify against docs/plans/zak-mockup-port/SPEC.md §3. My Leads now exposes Leads, Transactions, and one Refunds entry; /refunds is the live merged page, while /request-refund and /refund-status now redirect there. /reports redirects to /billing, and Reports leaves both desktop/mobile nav.
  • Payment & Budget now matches the mockup's compact single-screen shape without changing payment APIs: Add funds + Monthly budget form the two-card top row, Account status stays full width, and the old invoice generator/table moved into a new Invoices card styled after the mockup's invstrip. Card management stayed available by folding Stripe portal access into the Add Funds card instead of keeping a separate Payment Methods panel.
  • Mockup cleanup items landed: the mounted CommandPalette and ⌘K/search affordance are removed; legacy Reports.tsx, RequestRefund.tsx, RefundStatus.tsx, and CommandPalette.tsx were deleted after import checks; live-transfer UI copy/badges were removed from the buyer dossier and the dead frontend field references were trimmed while worker/database columns remain untouched.
  • Proof: bun run verify from the worktree root passed — app vitest green at 33 files / 256 tests, then vite build produced dist/assets/index-Cnm1Uoj6.js and dist/assets/index-Bpp2jD8Z.css.
  • Still owed before any live claim: walkthrough/deck screenshot refresh against the new /refunds and Billing routes, then the usual approval-gated merge/deploy proof.

2026-07-07 - Signup 500 root-caused: register made atomic, ledger repaired, worker logs on

  • Cam's live signup failed (console: POST /api/v1/auth/login 401 + a rendered 500). Evidence trail: his cam@velli.cc row existed with NO signup_bonus wallet row — /auth/register ran its two INSERTs as separate .run() calls, and a failure between them left a half-created account and threw an unhandled 500 (rendered as http_500). The 401 was him signing in before the account existed (the page opens on the Sign in tab).
  • Fixes: the users + wallet_transactions INSERTs now land in one DB.batch() (atomic); unknown error codes render friendly copy instead of raw http_500; observability.enabled turned on for worker soldi so the next prod 500 is diagnosable after the fact.
  • Data repair: inserted the missing Welcome-bonus ledger row for cam@velli.cc (WT_REPAIR_79a5e19e…, ledger now consistent with the $500 balance); removed the two repro accounts created during diagnosis.
  • Proof: new route test auth-register.test.ts asserts both INSERTs share one batch (fails against the old code); verify 31/251 green.

2026-07-07 - previews/ ⇄ app/ boundary made explicit after Zak's "changes missing" confusion

  • Zak's simplify+condense session (PR #147) edited the previews/ mockup and he expected app.soldi.cc to change. Audit confirmed every Zak PR is live on its intended surface — #147 was preview-only by its own description; the mockup→app port is un-started work.
  • Guardrails committed to main (2280609): "previews/ is mock-ups ONLY" rule in root CLAUDE.md + AGENTS.md (Codex reads AGENTS.md) and a STOP block atop previews/CLAUDE.md.

2026-07-07 - Flat-glass prod regression fixed: backdrop-filter restored in built CSS (PR #155)

  • Cam flagged the login page looking like a void. Root cause: hand-authored -webkit-backdrop-filter duplicates next to the standard property make Lightning CSS (Tailwind v4 pipeline) DROP the standard declaration from the minified build — every .glass/.glass-panel surface shipped with computed backdrop-filter: none in production. Dev builds are unminified, so vite-dev QA never saw it — the bug predates this week (visible in Zak's screenshots).
  • Fix: author the standard property only; the pipeline emits prefixed + standard correctly. Restores frost on login card, nav glass, and drawers app-wide. Polish pass consolidated the token block to @theme static + :root aliases (values byte-identical, verified on built dist).
  • Proof: verify 30/250 green; built-dist QA computed blur(18px) saturate(1.7); deployed worker d8ccd6a0; live /login re-screenshot (live-login-glass-20260707.png).
  • Process fix: visual QA must run against the BUILT dist (wrangler dev on app/dist or the live URL), never vite dev — minifier-only regressions are invisible in dev.

2026-07-07 - Public shop window live: masked browse, address = paid unlock, de-distressed copy (PR #154)

  • Server-side leak closed: /api/v1/market/leads and /api/v1/auctions* were serving the full street address unauthenticated in production — the "exact address unlocks on purchase" promise was client-side only. Pre-purchase SELECTs/DTOs are now city/county/zip-level; the exact address + owner identity is served exclusively by the ownership-gated /leads routes post-purchase. Regression test pins the public payload AND the SQL (no address/owner_name).
  • Guests can browse: /market renders logged-out (masked rows, Sign in/Sign up nav); guest Buy → /login; buying still requires auth + funded wallet (401/402/403/409 gates unchanged). Cam's model: auth wall on the data, not on the window-shopping.
  • De-distressed public copy: tab title → "soldi — Exclusive Seller Lead Marketplace"; login subtitle → "Sign in to claim exclusive seller leads."; Floor hero → "exclusive off-market seller leads".
  • Proof: verify 30 files / 250 tests + polish-pass browser QA green; deployed worker 76ccf00f (bundle index-BHEss8Gd.js); live: unauth market/auctions payloads carry zero address keys, guest UI shows Sign in/Sign up + masked rows (live-guest-market-20260707.png), authed demo pipeline card still returns the owned address. make-it-sexy/simpler pass applied (Market live-floor kicker, phase transitions, LeadDetail lock note).
  • In flight: Sequences engine PR #152 (32f/256t green) + Comps live-provider PR #153 (32f/260t green) from the Codex gpt-5.4 lanes — both merge-gated; migration 0024_* number collision noted on both (second to merge renumbers to 0025).

2026-07-07 - BETA DEPLOY: mobile shell + Realtime Wave 3 live on app.soldi.cc (B6-B12 green)

  • The held deploy shipped. After Zak flagged app.soldi.cc as stale, Cam directed the mac session to finish the handoff-dossier runbook (previews/soldi-mvp-handoff.html §08 / BETA_READINESS.md §2). Pre-deploy gate: in-repo bun run verify green (30 files / 249 tests, build assets/index-D9NHprHQ.js). bun run deploy:app → worker version 9c8b6452-1a0e-4ccd-b799-53dfc0344418; live bundle hash matches the local build; DO migration v1 applied (AUCTION_ROOM/FLOOR_FEED live); remote D1 clean at 0023.
  • Post-deploy battery green (B9): health/auth/authz, Market 3 rows, Pipeline staged counts, Territories standing-order 25000→26000→25000 round-trip, deposit 409 stripe_checkout_required, zero 5xx.
  • Realtime proven live (B10): wss://…/api/v1/rt/floor 101 + hello event with sold-history; LIVE floor ticker streaming in the browser; Room presence panel on /lead/:id. Spec correction: plain GET /api/v1/rt/floor 404s by design — only Upgrade: websocket requests route to the DO (app/worker/index.ts); the runbook's "plain GET → 200" probe was wrong.
  • Mobile shell proven live (B11): 375×812 production shots of Market/Leads/Territories/Billing/ Settings — scrollWidth=375 everywhere, console clean, chrome 132.5px; drawer opens grouped, navigates + closes on tap (artifacts/soldi-completion-2026-07/shots/live-*-20260707.png).
  • Deck refreshed (B12): realtime slide gets a real production screenshot; new "Mobile shell" slide with the live 375px shot (docs/walkthrough.html, docs/shots/*-20260707.png).
  • Two Codex gpt-5.4 lanes launched (tmx, worktrees) on the remaining red engines: feat/sequences-send-engine (SPEC_SEQUENCES §Implementation plan) and feat/comps-live-provider (SPEC_COMPS §Implementation plan, mock-default until keys exist). PRs to follow; no merge/deploy without approval.
  • Still on Cam (unchanged): D1 duplicate Stripe Customer, D4 admin@soldi.cc rotation, D5 test-mode ratification, D6 Zak "Text 2"; ops/previews surface deploys from the 07-07 entry below also remain approval-gated.

2026-07-07 - New ops/ surface: growth/ads/client briefs isolated off preview.soldi.cc

  • New fifth deploy surface ops/ (worker growth-ops-74b4, static assets, workers.dev only — no custom domain by design): the growth-side material previously served from preview.soldi.cc moved here, restoring the brand firewall in both directions (no FHC/client strategy on a soldi.cc host, no Soldi on FHC). Readable paths replace hash dirs: /fhc-growth/, /growth-ops-dossier/, /fhc-affiliate/ (draft, first deployable home), /google-call/, /aj/, /elite-flippers-meta/, /elite-flippers-launch/, /agent-ads/ — grouped by concern on a new root index (FHC growth · Google · Elite Flippers × Meta · Agent ops). The unguessable hostname is the access control; everything stays noindexed.
  • Single-copy model on ops/: no working-copy⇄deployed-copy twins — public/<slug>/index.html is the only copy (drift-by-design eliminated for the moved docs; verified all 13 previews twins byte-identical before the move, so nothing was lost). Internal cross-links between the moved docs rewritten to the new slugs; stale "keep byte-identical twin" footer fixed in /agent-ads/.
  • previews/ slimmed to Soldi-only: root index now Product / Network / Dev docs (Market mocks, research, affiliate, MVP handoff, Stripe runbook); Strategy-&-briefs section gone. previews/CLAUDE.md rewritten (Soldi-only rule, corrected stale "root 404s" note, full twin list incl. the previously undocumented marketplace-client/mkt-d64dc6e2 + dev-doc pairs).
  • Wiring + docs: root package.json gains ops workspace + deploy:ops; surface maps updated in README.md, CLAUDE.md, AGENTS.md; live pointers updated in docs/implementation-notes/{fhc-organic-growth, meta-ads-elite-flippers}.md, docs/content/ROADMAP.md, docs/content/fhc/launch/README.md, sites/fhc-pages/docs/GO-LIVE-RUNBOOK.md (dated history left as-is). Public docs reference the surface only as "unlisted growth-ops" — the hostname never appears on a published page.
  • Not deployed yet (deploys are approval-gated): needs bun run deploy:ops (first deploy mints the workers.dev URL) + bun run deploy:previews (removes the moved files from the soldi.cc host). Old preview.soldi.cc brief URLs will 404 after that — resend the new links to anyone holding them.

2026-07-06 - Wave 2 C+D: repo slash-commands, live-proof tooling, CI budget cut

  • .github/workflows/ci.yml rewritten: dorny/paths-filter job-level gating (no-checkout API filter job), concurrency cancellation, bun install cache, fetch-depth:0 removed. Measured baseline 61 billable min / last 30 PR pushes (avg 2.03/push; 20 of 30 were docs/previews-only paying for app verify + fhc setup-burn); estimated post-fix ~40-43 min (-30-35%), docs-only pushes 2→1 min. Branch protection is plan-gated (403) so job-level skips can't brick required checks; job names preserved. Validated via action-validator + js-yaml (no PR run possible from sandbox — eyeball the first real run).
  • New .claude/commands/ (six quirk-encoding runbooks + index) and tools/repo/ (live-proof.sh, beta-gates.sh). live-proof tested on all four surfaces (previews 6/6 sha256, fhc correctly flagged the known live-drift post lag-retry); beta-gates scoreboard matches BETA_READINESS and proved the .env token reads remote D1 (B8 probe: no unapplied migrations).
  • Note: docs/implementation-notes/wave2-tooling-ci.md. Next up: watch the first PR run of the new workflow; wire ui-validate verdicts into beta-gates when the harness lands; flip the pre-shell bundle baseline after B7.

2026-07-06 - Beta-readiness spec + docs completeness pass (stream A, docs-only)

  • Authoritative beta spec: docs/plans/mvp-build-public-release/BETA_READINESS.md — testable "beta-ready" definition B1-B15 (B1/B2/B14 already MET), the mac-session deploy runbook (375px proof gates for Market/Leads/Territories/Billing/Settings, bun run deploy:app, the deliberate mobile-shell + Realtime-Wave-3 DO-migration coupling, post-deploy battery incl. GET /api/v1/rt/floor 404→200 realtime room), rollback notes (fix-forward via git revert; wrangler rollback may be blocked across the DO migration; additive DO safe to leave), and beta-tester onboarding (demo vs real accounts, test-card funding, 10-flow exercise list, known limitations). Planning packet refreshed around it (open-decisions.md, release-readiness.json, README.md).
  • Post-MVP slices specced to implementation-ready: SPEC_SEQUENCES.md §Implementation plan (send engine: Resend REST via fetch@velli/email-relay is not a repo dependency; claim-before-send idempotency, 50/tick rate cap, SEQUENCES_SEND_ENABLED kill switch, unique (enrollment, step) index, full test plan; schema 0007 + cron already exist) and SPEC_COMPS.md §Implementation plan (CompsProvider seam, ATTOM+Anthropic pipeline, first-party cost/latency, honest fallback-to-mock; human prerequisite: procure ATTOM_API_KEY + ANTHROPIC_API_KEY — neither exists anywhere).
  • Docs truth pass: SHARE_WITH_ZAK.md no longer lists realtime as live buyer product (moved to "built NOT deployed" with the deploy pointer) and now carries the Zak "Text 2" DRAFT behind two named gates (P2 decided; shell proof + deploy); /auth/me 200-{"user":null} ADR added to DECISIONS.md (deliberate SPA bootstrap, auth.ts:174, live-verified); ROADMAP "Where we are" records the shell landing + beta spec; TESTING_PLAN's stale "Stripe unproven" gap closed (dated) and the shell-proof gap added. New decision surfaced for Cam: ratify Stripe test mode for the beta (D5).
  • Handoff artifacts refreshed (both twins byte-identical, HTML-parse checked): soldi-mvp-handoff.html §03 now carries 5 decisions with next-action/unblocks/safe-default and §04/§06/§08 point at the beta spec; stripe-payments-runbook.html §05 gains the safe default + test-mode-for-beta note.
  • Verification: docs-only diff (no app source); bun run build:docs green (10 internal + 2 client docs); live spot-probes re-confirmed bundle assets/index-CXgZFR3a.js, rt/floor 404, /auth/me null-user.
  • Next: mac session executes BETA_READINESS §2; Cam clears §5 (D1-D6); then beta invites + Text 2.

2026-07-06 - FHC go-live runbook, engineering specs, Deadline-H1 unification (stream B)

  • NEW sites/fhc-pages/docs/GO-LIVE-RUNBOOK.md: the single authoritative 11-step launch sequence — Cam tokens → build+audit gate (warnings 529→~0 once the pixel is real) → deploy (exit-1 domain-attach benign) → curl live-proof battery → IndexNow → GSC staged calendar (priority wk1 / states wk2 / situations wk3 / cities+static wk4) → Bing → GBP → Velli → tracking verification, each step with owner/preconditions/command/success-check/rollback.
  • NEW docs/content/fhc/launch/specs/ (5 + index): Spanish /es/ landers (M), server-side Meta CAPI (S-M, ships dark), true per-page sitemap lastmod (M, input-hash manifest), internal-link classes 2-3 (S), 4-engine GEO citation tracker (M).
  • Code: unified the 50 generated calculators' "Foreclosure Timeline Calculator" H1/i18n/embed/ICS strings + JSON-LD app name to "Deadline" (drift from the meta pass — title, slug, ES dict, and the handcrafted IL flagship already said Deadline); rebuild + audit identical before/after (528 pages, 0 blockers, 529 warnings).
  • Truth pass: sites/fhc-pages/CLAUDE.md (page count 263→540 files/528 audited; privacy-placeholder note replaced with the live Chicago-address fact), RESUME-2026-06-18.md marked SUPERSEDED, Velli backlink doc status banner, fhc-growth-handoff artifact twins refreshed (Cam switch table, spec pointers, runbook links) and kept byte-identical. No deploys, no submissions.

2026-07-06 - Ads & analytics ops: EF launch gates + weekly-report spec (stream C)

  • Tightened Elite Flippers Meta launch docs to deadline-ready. previews/{,public/}elite-flippers-meta-plan.html: G0-G6 gate sequence (launch-ready = G0-G5, launched = G6), 10-item credential handoff with Business Manager paths + verify commands, first-campaign spec, Housing split into a classification decision (the efm strategy doc says EF coaching is NOT Housing — open G0 call for Cam) + CLI-flag verification (official command reference re-fetched: flag absent from docs; on-Mac --help check is the hard precondition; Marketing API fallback documented).
  • previews/{,public/}agent-ads-ops.html: weekly report v1 spec (GCP service-account runbook, runReport proof, metrics, /ads-weekly/ dated-snapshot convention, 6 done-criteria), honesty flags expanded (incl. Special Ad Audiences likely discontinued 2023; unofficial meta-ads-cli package footgun).
  • docs/implementation-notes/meta-ads-elite-flippers.md updated with blocker-by-owner table (Cam vs Abdullah) + today's session entry. Twins byte-identical; zero live mutations.

2026-07-06 - Four handoff artifacts indexed + deployed to preview.soldi.cc

  • Deployed the preview surface with the day's four new static artifacts indexed under Dev docs on the preview root: /soldi-mvp-handoff.html (MVP completion dossier), /stripe-payments-runbook.html (payments decision-of-record + operator runbook), /fhc-growth-handoff.html (FHC organic action board + link-engine runbook), /agent-ads-ops.html (agent-run ads/analytics tooling plan). The amended growth-ops dossier (/gops-74b478ea/ Cloudflare hype-ledger update) shipped in the same upload.
  • Deploy: npx -y wrangler@4 deploy --config previews/wrangler.jsonc (run outside the repo per the linux-sandbox node_modules constraint), Worker version af2a8ef3-d95d-47a6-96a4-4f9d71d4884b, 6 new/modified assets uploaded.
  • Live proof: all five changed pages plus the root index fetched with curl -sL and SHA-256-matched byte-for-byte against the local previews/public/ twins (one transient cache mismatch on first read of /soldi-mvp-handoff.html; re-fetch + diff confirmed identical).
  • This closes the 2026-07-06 dual-lane pass (Soldi MVP completion + FHC organic growth, entries below). Approval-gated next actions live in the artifacts: app deploy (mobile shell + Wave 3 DO migration, after mac-side screenshot proof), FHC redeploy + IndexNow/GSC/Bing submissions, P2 duplicate-Customer decision, Meta pixel + verification tokens.

2026-07-06 - FHC organic growth: meta pass, internal-link engine, growth handoff artifact

  • Meta-length pass (fhc): all 34 over-length titles + 66 over-length descriptions fixed at the source — calculator-state.eta (new {State} Foreclosure Deadline Calculator | Fair Home Cash title + fixed ≤155-char description; the old one interpolated rules.process, up to 552 chars for Oregon), situation-templates.ts (stop-foreclosure title/desc, divorce desc — patterns length-checked programmatically across all 51 state names), il-situations.ts (3 IL deep-page descs). bun run audit: 629 → 529 warnings, 0 blockers; every remaining warning is the FHC_META_PIXEL_ID placeholder awaiting Cam's real pixel ID.
  • Verification-tag readiness: google-site-verification / facebook-domain-verification / new msvalidate.01 (FHC_BING_VERIFICATION) render only when their env token is set — no more empty content="" tags; calculator pages previously had none at all. Verified both ways (token set → renders on all page types; unset → absent).
  • Branded self-hosted OG card: og:image/twitter:image sitewide → /og-card.jpg (1200×630, 80 KB, composited from the existing fhc-cover.png hero + brand marks — no new photography), replacing hotlinked unsplash cards; og:image:width/height/alt added; hero rendering untouched.
  • Embedding internal-link engine: sites/fhc-pages/tools/internal-links.ts — embeds all 531 indexable dist pages (text-embedding-3-small, sha256 resumable cache), similarity minus the 7,543 existing links, ranked recs at tools/output/internal-link-recs.{json,md}. Cold run 602,630 tokens ≈ $0.012 / 5 s; warm rerun 0.8 s. First wired class: every state calculator now links its state's stop-foreclosure guide (top systematic gap, sim ~0.91 × 50 states; guide already linked back) — 2 links/page in dist, audit stays 0 blockers.
  • Strategy/truth pass: dossier hype-ledger Cloudflare pay-per-crawl entry amended (dated) for the 2026-07-01 Cloudflare pivot in both twins (previews/gops-dossier.html, previews/public/gops-74b478ea/index.html, kept byte-identical); docs/content/fhc/launch/README.md corrected with a dated banner (todos 01/02 done 2026-06-26; "Search Console — DONE" was overstated — nothing has ever been submitted). New note: docs/implementation-notes/fhc-organic-growth.md.
  • Handoff artifact: previews/fhc-growth-handoff.html (+ byte-identical deployable twin in previews/public/) — live-state snapshot with probe evidence, done-matrix, the organic action board (owner/effort/impact/next command per item), frontier-strategy ranking incl. debunked items (llms.txt as lever, blanket crawler blocking), Cam-blocked list, env quirks, this-week list. Cross-links the dossier, Elite Flippers plan, and agent-ads-ops. Not deployed/indexed — orchestrator owns that.
  • Approval-gated, prepared + dry-run-verified, NOT executed: fhc redeploy (wrangler deploy --dry-run green, 561 assets — live pages still serve the OLD titles and 404 on /og-card.jpg until Cam approves); IndexNow submit (bun run indexnow dry-run: 137 priority URLs, key live + byte-matched today); GSC staged sitemap submission (priority sitemap first); Bing Webmaster; Velli placements (docs/content/research/velli-fhc-backlinks-2026-06.md).
  • Verification evidence: rebuild 540 files/1.7 s; audits before/after in this entry; live probes 2026-07-06 (curl -sL) — homepage 200, IndexNow key byte-match, Nebraska calc live title = old 76-char version (drift proof that a deploy is owed).
  • Next: Cam's five switches (pixel ID, 3 verification tokens, GBP claim, Velli access, counsel); approved redeploy + IndexNow/GSC/Bing chain; agent lanes — next link classes (city metro clusters, situation cross-links), true per-page sitemap lastmod, Agent-class bot access check, hyper-local situation×neighborhood batch, /es/ landers.

2026-07-06 - MVP completion pass: mobile buyer shell, payments decision, docs truth pass, handoff artifacts

  • Payments decision settled and recorded: stay Stripe; Clerk Billing rejected — confirmed by Cam 2026-07-06, matching the research conclusion (Clerk Billing wraps Stripe, adds +0.7%/txn, Plan-ID-only checkout, no escrow/payout primitives, would entangle live PBKDF2 auth). ADR added to docs/content/DECISIONS.md with reversal condition and sources.
  • Docs truth pass: SHARE_WITH_ZAK.md payments bullet and client-session line no longer claim Stripe is parked (it went live 2026-07-03, P1 GREEN + full B7 battery per artifacts/soldi-completion-2026-07/COMPLETION_TRACKER.md); docs/content/ROADMAP.md stale "hard proof gap"/"waits on secrets" wording superseded by a dated P1/P2 paragraph; docs/implementation-notes/README.md corrected (lead-consent-audit → shipped, /admin routed at app/src/App.tsx:50; mvp-ship-loop → superseded); mvp-ship-loop.md carries an explicit superseded-by-platform-completion banner.
  • Mobile buyer shell (last open MVP code gap) implemented: new app/src/layouts/MobileNav.tsx phone drawer (≤640px) — compact current-section button opens a grouped menu (Market / My Leads / Account / Admin) with the disabled Floor pill inside the menu; TopNav phone chrome is one 52px row; ScoreboardBar becomes a one-line scrollable status strip (kill-switch first). Tablet 641–920px keeps the segmented rail; desktop unchanged. First-viewport chrome at 375px drops from ~264px to ~130px by CSS accounting.
  • Verification: sandbox linux copy (fresh bun install) bun run verify green — typecheck, 30 files / 245 tests (5 new MobileNav tests), build assets/index-CFrs7sov.js. In-repo tsc -b green after porting. In-repo tests/build remain blocked by the known macOS-native binary mismatch (environment artifact, not code). No headless Chrome in this sandbox — 375px screenshot proof, deck/walkthrough refresh, and the owner-approved app deploy remain for a mac-side session (that deploy also applies Realtime Wave 3's DO migration).
  • Live QA battery (non-destructive, demo account, curl -sL): 21/21 probes passed on app.soldi.cc — health + bundle assets/index-CXgZFR3a.js (no drift), auth 200/401, market rows + dossier contacts, Territories standing-order round-trip restored, pipeline stage counts, Billing 409 stripe_checkout_required/wallet/checkout stripe_live URL (not visited), admin 403/401 boundaries, realtime 404 as expected. Informational only: unauthenticated /auth/me returns 200 {"user":null} by design; Market filters are client-side; /user/preferences is PATCH-only. Zero 5xx.
  • Handoff artifacts authored (editing + deployable twins, not yet indexed/deployed — orchestrator owns that): previews/soldi-mvp-handoff.html (status board, decisions, QA record, environment quirks, this-week list) and previews/stripe-payments-runbook.html (integration map with file:line pointers, production state, operating/testing procedures, P2 options, Connect roadmap), cross-linked.
  • Next: Cam's P2 duplicate-Customer decision (minutes); mac session for mobile-shell screenshot proof + deck refresh + approved app deploy; then Zak "Text 2".

2026-07-06 - Elite Flippers Meta plan published to preview surface

  • Added the Elite Flippers Meta Ads launch-control artifact to the deployable preview static tree as previews/public/elite-flippers-meta-plan.html. The top-level previews/elite-flippers-meta-plan.html remains the editing copy.
  • Indexed the artifact on the live preview root under a new Dev docs group with the path /elite-flippers-meta-plan.html.
  • Verification before deploy: bun install had no changes; bun run verify passed 29 test files / 240 tests and built assets/index-CXgZFR3a.js; local headless Chrome rendered previews/public/index.html and the public plan page.
  • Deployment: bunx wrangler deploy --dry-run --config previews/wrangler.jsonc read 19 static assets successfully, then bun run deploy:previews uploaded /index.html and /elite-flippers-meta-plan.html to Worker version 0f6ddaf6-843c-4eab-a24b-7c287c0f8e00 on preview.soldi.cc.
  • Live proof: https://preview.soldi.cc/elite-flippers-meta-plan.html?cb=20260706-meta byte-for-byte matched local SHA-256 51a88de6aa112572fdd9e8fe7a18167b89ea0c3c9404dbb4660d997f3ebc68a2; https://preview.soldi.cc/?cb=20260706-meta contains the Dev docs card and link. The plural host previews.soldi.cc does not resolve; the configured custom domain is singular preview.soldi.cc.
  • Next: continue the Meta account credential handoff; no Meta auth or ad-account mutation has occurred.

2026-07-06 - Elite Flippers Meta Ads CLI foundation and static plan

  • Installed Meta's official meta-ads CLI version 1.1.0 in an isolated Python 3.13 virtual environment at /Users/cameronolechowski/.codex/tools/meta-ads-venv after confirming the default Python 3.14 could not install the package because Meta's current PyPI wheels target CPython 3.12/3.13.
  • Verified the CLI command surface locally: meta --version returned 1.1.0, meta ads --help exposed campaign/ad set/ad/creative/catalog/dataset/insights commands, and meta auth status correctly reported unauthenticated until ACCESS_TOKEN is provided.
  • Added preview-only static artifact previews/elite-flippers-meta-plan.html for Abdullah Ghaffar's Elite Flippers brand. The artifact tracks setup gates, account prerequisites, read-only proof commands, paused-draft campaign posture, Meta housing special-category review, operating rules, and a launch sequence from account ground truth through human activation.
  • Created implementation note docs/implementation-notes/meta-ads-elite-flippers.md and indexed it. The note records the credential-safe posture, open questions, and the decision not to use unofficial similarly named Meta CLI packages.
  • Verification: bun install completed with no changes; bun run verify passed 29 test files / 240 tests and built assets/index-CXgZFR3a.js. Headless Chrome rendered the static artifact at desktop and mobile widths; final mobile proof is /tmp/elite-flippers-meta-proof/mobile-final6.png.
  • Next: Cam needs to provide or create a dedicated Meta system-user token plus Elite Flippers AD_ACCOUNT_ID, BUSINESS_ID, Page/Instagram asset, pixel/dataset ID, destination URL, and launch budget/approval rules before any authenticated CLI read or paused campaign draft.

2026-07-03 - F4 live QA: mobile Territories density fix

  • Cam's narrow /territories screenshot exposed a second mobile failure that the prior scrollWidth === innerWidth proof missed: the shell no longer overflowed, but the actual Territories table began roughly 1007px below the top of a 375px viewport, leaving the first screen dominated by chrome, copy, and tall stat cards.
  • PR #139 tightened the mobile Territories composition without touching standing-order data wiring: phone-width copy is tighter, the duplicate top Add button is hidden at <=640px, and mobile stats use compact two-column tiles instead of four full-width cards.
  • Verification: local bun run verify passed 29 files / 240 tests and built assets/index-CXgZFR3a.js; PR CI passed bun verify and conditional FHC audit. UI file line counts remain under 400: Territories.tsx 367 lines, Territories.parts.tsx 393 lines.
  • App deploy succeeded as Worker version 8a2ae336-4aa9-427e-9da6-76764da39707. Freshness proof: https://app.soldi.cc/territories HTML returned cf-cache-status: HIT but referenced assets/index-CXgZFR3a.js; live asset SHA-256 matched local app/dist/assets/index-CXgZFR3a.js.
  • Live browser proof: at 375px, /territories rendered scrollWidth=375, active Territories first, duplicate top Add hidden, two-column stat tiles, 4 table rows, and table top 648px; at 711px, scrollWidth=711, active Territories first, table top 679px. Both proof runs returned no Chrome DevTools error-console output.
  • Evidence: artifacts/soldi-completion-2026-07/shots/mobile-territories-density-receipt-20260703.txt, mobile-territories-density-live-375-20260703.png, and mobile-territories-density-live-711-20260703.png.
  • Next: P2 still waits on the historical duplicate Stripe test Customer cleanup/acceptance decision; do not send Text 2 yet.

2026-07-03 - F4 live QA: demo wallet held-balance normalization

  • F4 wallet sanity found the demo buyer had a legitimate positive Stripe-funded wallet balance but a corrupted negative hold: remote D1 showed demo@soldi.cc at balance=11700, held_balance=-73000, and no active winning auctions. Because available funds are computed as balance - held_balance, Billing showed available funds above wallet balance.
  • PR #135 fixed the invariant without editing wallet balance: publicUser and currentUser now clamp negative held balances on read, and migration 0023_normalize_negative_held_balances.sql normalizes persisted held_balance < 0 rows to zero.
  • Verification: focused cd app && bun run test worker/users.test.ts passed 1 file / 2 tests; full bun run verify passed 29 files / 240 tests and built assets/index-BeilEzBd.js. CI passed bun verify in 57s and conditional FHC audit in 8s.
  • Remote migration 0023_normalize_negative_held_balances.sql applied. D1 proof now shows demo@soldi.cc with balance=11700, held_balance=0, and available=11700; negative-held users are 0; active demo winning holds are 0; migration list shows no unapplied migrations.
  • App deployed Worker version 6edcb9ec-f07a-481d-a9fe-eb2a52edaa7e. Live Billing proof via ?demo=1 rendered Payment & Budget, WALLET BALANCE $117, $117 available, Add funds, scrollWidth=1280, and browser error logs [].
  • Freshness: https://app.soldi.cc/billing HTML returned cf-cache-status: HIT but referenced assets/index-BeilEzBd.js; live asset SHA-256 matched local app/dist/assets/index-BeilEzBd.js.
  • Evidence: artifacts/soldi-completion-2026-07/shots/f4-demo-wallet-held-normalization-d1-20260703.txt, f4-demo-wallet-held-normalization-live-proof-20260703.json, f4-demo-wallet-held-normalization-live-billing-20260703.png, and f4-demo-wallet-held-normalization-freshness-20260703.txt.
  • Next: continue F4 cleanup/export and keep P2 open until Cam decides how to handle the historical duplicate Stripe test Customer; do not send Text 2 yet.

2026-07-03 - F4 live QA: proof-ghost cleanup checkpoint

  • Exported the remote D1 database before cleanup to /tmp/soldi-remote-d1-export-before-f4-cleanup-20260703.sql (local-only, not committed because it contains contact data). SHA-256: 55a02074440f88004b0d0bbbe1fd5bdde0bb89f06ca233933d824f82e3366664.
  • Cleanup candidates were queried by explicit proof/test IDs and sources before mutation. The cleanup removed two disposable proof users, their two signup wallet rows, nine stale proof/test leads, nine lead-consent rows, four review rows, and five FHC ingest-event rows.
  • Preserved the three f4_demo_inventory leads because they are explicitly synthetic demo inventory for live Market filter proof, with 555-01xx phones and @example.com emails. Also preserved the Stripe-funded C1 owned proof portfolio/lead so the bought-lead proof remains renderable.
  • Post-cleanup D1 proof: remaining_disposable_users=0, remaining_deleted_proof_leads=0, f4_demo_inventory_available=3, and c1_owned_proof_portfolios=1.
  • Evidence: artifacts/soldi-completion-2026-07/shots/f4-d1-cleanup-checkpoint-20260703.txt and f4-proof-ghost-cleanup-20260703.txt.
  • Next: commit cleanup evidence and continue F4 formal live proof; P2 still waits on the duplicate Stripe test Customer decision.

2026-07-03 - F4 live QA: post-cleanup browser proof

  • Re-ran the key buyer-parity F4 proof against live app.soldi.cc after the held-balance fix and proof-ghost cleanup.
  • Market proof: live /market?demo=1 served the 3 explicit f4_demo_inventory rows; distress filters changed row counts as expected (Probate=1, Divorce=1, All=3); Map mode rendered an honest MAP VIEW / Coming soon state with the visible lead list instead of a dead fake map; browser errors were 0.
  • Leads proof: live /leads?demo=1 rendered 24 owned rows, unnamedFields=0, row click opened the dossier drawer, and browser errors were 0.
  • Territories proof: live /territories?demo=1 rendered 4 active rows, unnamedFields=0, and the Cook pre-foreclosure controls persisted through reload. The reversible test changed $250/weekly cap 10 to $255/11, confirmed after reload, then restored to $250/10 and confirmed after reload; browser errors were 0.
  • Mobile proof: 375px Market, Leads, and Territories all had scrollWidth=375, unnamedFields=0, and browser errors 0.
  • Evidence: f4-post-cleanup-market-proof-20260703.json, f4-post-cleanup-leads-proof-20260703.json, f4-post-cleanup-territories-persist-proof-20260703.json, f4-post-cleanup-mobile-proof-20260703.json, plus matching screenshots under artifacts/soldi-completion-2026-07/shots/.
  • Next: P2 remains IN_PROGRESS on the historical duplicate Stripe test Customer decision; do not send Text 2 yet.

2026-07-03 - F4 live QA: Billing checkout-return guard

  • The legitimate Stripe wallet-normalization pass credited the demo wallet but exposed a real Billing return bug: the /billing?checkout=success redirect produced a blank Billing screenshot with repeated React max-update-depth errors.
  • Patched app/src/pages/Billing.tsx so the checkout-return handler is idempotent per userId:location.search and depends on stable session fields (session.user?.id, session.refresh) instead of the whole session context object.
  • Added app/src/pages/Billing.test.tsx to pin the return behavior: Stripe success refreshes the session once, strips the query back to /billing, and keeps the page rendered.
  • Verification: focused Billing Vitest passed 1 file / 1 test; full bun run verify passed 28 files / 238 tests and built assets/index-BeilEzBd.js.
  • PR #133 passed CI (bun verify and conditional FHC audit), merged at 0247406, and deployed as Worker version 17316e33-ad7d-47cf-94f4-cb898f71e5a7.
  • Live freshness: https://app.soldi.cc/billing HTML returned cf-cache-status: HIT but referenced fresh assets/index-BeilEzBd.js. Live /billing?checkout=success proof via demo auth cleaned the URL to /billing, rendered Payment & Budget, Wallet balance, and Add funds, had scrollWidth=1280, and browser error logs 0.
  • Evidence: artifacts/soldi-completion-2026-07/shots/f4-billing-checkout-success-live-proof-20260703.json and f4-billing-checkout-success-live-fixed-20260703.png.
  • Next: continue the wallet-normalization evidence path and D1 Stripe deposit/event proof; do not send Text 2 yet.

2026-07-03 - F4 live QA: narrow buyer shell breakpoint fix

  • Cam's /territories screenshot exposed a live narrow-viewport failure band: the app was wider than the old 760px phone breakpoint, so desktop nav/scoreboard/ticker rules still applied and clipped the first viewport.
  • Patched the shared buyer shell only: TopNav, ScoreboardBar, and LiveTicker now use their compact rules through 920px. This makes the active route deterministic, pushes disabled Floor out of the first narrow view, hides the Coming Soon badge in compact mode, wraps utility chips, and keeps the ticker stable.
  • Verification: bun run verify passed 27 files / 237 tests and built assets/index-CLEnGqU2.js. Local worker proof at 375px, 711px, and 880px showed scrollWidth === innerWidth, active tab Territories, disabled Floor ordered after real tabs, soonBadgeDisplay=none, no unnamed fields, and zero browser error logs.
  • PR #131 passed CI (bun verify 56s; conditional FHC audit 10s), merged at 244d976, and deployed as Worker version 1843183a-3df3-47d0-9667-008de97f8341.
  • Live freshness: https://app.soldi.cc/territories HTML returned cf-cache-status: HIT but referenced fresh assets/index-CLEnGqU2.js. Live browser proof at 375px, 711px, and 880px showed scrollWidth === innerWidth, active tab Territories, disabled Floor ordered after real tabs, soonBadgeDisplay=none, no unnamed fields, and zero browser error logs.
  • Evidence: artifacts/soldi-completion-2026-07/shots/f4-narrow-shell-local-proof-20260703.json, f4-narrow-shell-live-proof-20260703.json, and matching local/live screenshots.
  • Next: resume wallet-normalization/Billing checkout-success debugging; do not send Text 2 yet.

2026-07-03 - F4 live QA: Leads field-name regression fixed

  • F4 browser QA found a real form-safety regression on live /leads: 24 owned-lead status selects rendered with aria labels but no stable name/id on both desktop and 375px.
  • PR #129 fixed app/src/pages/Leads.tsx by naming each status select leadStatus-${portfolioId}. No data wiring, stage movement, money movement, or layout changed.
  • Verification: focused BuyerScreens Vitest passed 1 file / 5 tests; full bun run verify passed 27 files / 237 tests and built assets/index-DIJ4pPnC.js. CI passed bun verify in 56s and conditional FHC audit in 11s.
  • App deployed Worker version 0ec15132-96f6-4354-9f0e-0e8040a07296. Live /leads served assets/index-DIJ4pPnC.js; desktop and 375px re-proof both showed unnamedFields=0, 24 named selects, zero console/page/network errors, and mobile scrollWidth=375.
  • Evidence: artifacts/soldi-completion-2026-07/shots/f4-leads-field-name-fix-local-20260703.txt, f4-live-leads-field-names-proof-20260703.json, and the matching desktop/mobile screenshots.
  • Remaining F4 blockers: demo wallet is still negative and must be normalized via legitimate flows; proof-ghost cleanup/export still needs to run; P2 still waits on the duplicate Stripe test Customer decision.

2026-07-03 - Mobile shell active-nav live hotfix

  • Cam's follow-up /territories mobile screenshot showed the earlier shell patch still had a failure mode: if the horizontal rail did not scroll the active item into view, disabled Floor plus Coming Soon dominated the first viewport.
  • PR #127 fixed that by making mobile CSS order the active nav item first, pushing disabled Floor to the end of the rail, hiding the Floor Coming Soon badge on mobile, and forcing the mobile ticker to truncate with text-overflow: ellipsis instead of hard-cutting at the right edge.
  • Verification: local bun run verify passed 27 files / 237 tests and built assets/index-B3bTEkHq.js; CI passed bun verify in 56s and conditional FHC audit in 8s.
  • App deployed Worker version b557de2f-4589-4173-806c-9fb679dbcc2f. Custom-domain HTML still returned cf-cache-status: HIT, but served the fresh assets/index-B3bTEkHq.js; live asset response was HTTP 200 with cf-cache-status: MISS.
  • Live authenticated 375px proof on https://app.soldi.cc/territories passed: scrollWidth=375, active tab Territories at 17px, disabled Floor at 488px, soonBadgeDisplay=none, ticker textOverflow=ellipsis, zero console messages, and zero 4xx/5xx responses. Evidence: artifacts/soldi-completion-2026-07/shots/mobile-shell-active-nav-receipt-20260703.txt and mobile-shell-territories-active-nav-live-375-20260703.png.
  • Next: resume F4/P2 platform-completion proof. Do not send Text 2 yet.

2026-07-03 - Stripe Customer reuse fix and F2 proof progress

  • F1 is now GREEN: Cam completed the Stripe sandbox setup, wrangler secret list --config app/wrangler.jsonc shows FHC_INGEST_SECRET, SESSION_SECRET, STRIPE_SECRET_KEY, and STRIPE_WEBHOOK_SECRET, and dashboard webhook delivery later proved 200 OK to https://app.soldi.cc/api/v1/webhooks/stripe.
  • F2 gate/checkout/webhook proof progressed: authenticated /payments/deposit now returns 409 stripe_checkout_required; /wallet/checkout returns a hosted https://checkout.stripe.com/... URL; hosted Checkout credited the demo wallet by $10; D1 shows the wallet deposit and processed Stripe event; dashboard resend stayed idempotent with no double credit.
  • Portal proof found a real defect: the first live Checkout + Portal attempt left two Stripe test Customers for demo@soldi.cc. PR #123 fixed the app by creating/reusing the persisted Stripe Customer before hosted Checkout and passing that customer into the Checkout Session. CI passed bun verify and conditional FHC audit; app deployed Worker version cce7cd23-4fcc-4ffa-9821-5d43446c1636. Post-fix live checkout proof did not create a third Customer.
  • Re-ran C1 with Stripe-funded balance using a clearly synthetic lead: L_MR5KWTP2_284F9705005DC4F926B4821F at 999 Proof Battery Ln, $10 price, source session_proof_admin. Live admin API created/approved it; live Market API bought it as demo; D1 shows the $10 Stripe deposit followed by the $10 market charge, plus portfolio PF_MR5KWU4V_1D042A330C2173FCFFDD0C38, stage, and delivery rows. Clean browser proof renders the dossier contact fields with zero app console errors.
  • Verification: PR #123 local bun run verify passed 27 files / 237 tests and built assets/index-DwGNid5v.js; CI bun verify passed; live Billing desktop and 375px in-app browser proof served assets/index-DwGNid5v.js, scrollWidth=375 on mobile, and error logs [].
  • Next: P2 remains IN_PROGRESS until Cam approves deleting the older pre-fix duplicate Stripe test Customer or explicitly accepts the final receipt calling it out as a documented pre-fix artifact. Do not send Text 2 yet.

2026-07-03 - Platform completion mobile shell hotfix local proof

  • Cam's live /territories mobile screenshot exposed a shared shell regression: compressed top nav, clipped budget row, and ticker text landing mid-word before the Territories content.
  • Locally patched the shared buyer shell only: mobile TopNav now uses a brand/account row plus masked horizontal tab rail with the active tab scrolled into view, ScoreboardBar wraps chips instead of clipping them, LiveTicker stops the marquee on narrow screens and ellipsizes one stable item, and the main layout uses tighter mobile padding with global x-overflow clamped.
  • Verification: bun run verify passed 27 files / 235 tests and built assets/index-BQWg1Ans.js. Local authenticated 375px browser proof on /territories showed scrollWidth=375, active tab Territories, clean app console after excluding Vite/dev favicon/local websocket noise, and screenshot artifacts/soldi-completion-2026-07/shots/mobile-shell-territories-local-auth-375-masked-20260703.png.
  • PR #121 merged at 8a0d9ac; CI passed bun verify and conditional FHC audit. App deployed Worker version 3cb9f0d5-b65f-4e1a-a53d-f11a9e880403; live https://app.soldi.cc/territories served assets/index-DwGNid5v.js, matching local. Live authenticated 375px proof passed with scrollWidth=375, active tab Territories, account shell present, no console messages, no 4xx/5xx responses, and screenshot artifacts/soldi-completion-2026-07/shots/mobile-shell-territories-live-auth-375-20260703.png.
  • Next: return to the P2 Stripe checkout proof lane.

2026-07-03 - Platform completion F3: review fixes local proof

  • Final-session F3 review lanes completed under tmx and wrote three evidence reports: correctness/money, security/authz, and UX/consistency. Reports are saved under artifacts/soldi-completion-2026-07/shots/f3-review-*.md.
  • Fixed the first confirmed money defects locally. Buy-now now counts the current high bidder's existing hold toward affordability and reduces that held balance when converting to the full buy-now charge. Cron settlement now claims the auction row first and only writes debit/charge/portfolio rows when that guarded claim changes exactly one row.
  • Tightened IngestLeadSchema.equityPct to 0..100, matching Admin manual supply validation.
  • Removed dishonest buyer UI affordances found by the UX lane: the Market "Just claimed" ticker no longer fabricates purchases from available leads, standing-order copy describes max-price auto-claim behavior, Territories now says "Active" instead of unsupported "Top-Bid", and the dead webhook button was removed.
  • Verification: targeted tests passed 3 files / 38 tests; full bun run verify passed 27 files / 233 tests with bundle assets/index-CEhm0lL1.js. This slice is not yet deployed or live-reproved; next is PR, CI, merge, app deploy, and live Market/Territories/API proof.
  • PR #118 merged at 0fee781; CI passed bun verify and conditional FHC audit. App deployed Worker version 93f01214-f5aa-4c97-bffd-8b62528b16f8. Live app.soldi.cc served bundle assets/index-CEhm0lL1.js; desktop and 375px Market/Territories proof showed no fake "Just claimed", no unsupported "Top-Bid", no dead webhook button, and zero console messages. Screenshots and receipt: artifacts/soldi-completion-2026-07/shots/f3-live-and-security-receipt-20260703.txt.
  • Started second F3 security hardening slice for the remaining R2 findings: password changes now invalidate old session cookies, and FHC ingest requires timestamped HMAC plus x-fhc-idempotency-key with D1 replay tracking. Also fixed the live mobile shell regression Cam flagged on /territories: top nav now wraps into a controlled horizontal tab rail, scoreboard chips stop clipping, and the ticker has stable mobile height. Verification: focused app tests passed 4 files / 53 tests; FHC sender test passed 1 file / 3 tests; full bun run verify passed 27 files / 235 tests with bundle assets/index-CzzPzi4x.js; cd sites/fhc-pages && bun run audit passed 528 pages / 0 blockers. Needs PR, remote D1 migration 0022, app deploy, FHC deploy, and live signed-replay/mobile proof.
  • PR #119 merged at bdb6ed5; CI passed bun verify and conditional FHC audit. Remote D1 migration 0022_ingest_idempotency_and_session_revocation.sql applied and bunx wrangler d1 migrations list soldi --remote --config app/wrangler.jsonc later returned no unapplied migrations. App code deployed as Worker version 789051be-446b-4fce-bc07-a61be4cd85cf; current app/FHC versions are secret-change versions after a same-value FHC ingest secret rotation for proof (8ef6d0c7... app, 68c81094... FHC).
  • Live F3 proof is now GREEN. app.soldi.cc served assets/index-Bu2BmY1K.js, matching local. 375px Market and Territories browser proof showed document width 375, stacked nav/scoreboard/ticker/main shell, and zero console messages. Live password-change proof registered disposable f3-session-revoke-1783118924@example.com, changed its password, proved the old cookie returned user=null, the new cookie worked, old password login failed 401, and new password login worked 200.
  • Live FHC security proof passed after rotation: custom-domain FHC form submission forwarded to Soldi post-rotation, and direct signed replay event f3-security-replay-1783119111883 created exactly one lead, then returned duplicate receipts on second/third same-key POSTs; D1 fhc_ingest_events and leads counts confirmed idempotency. Evidence is appended in artifacts/soldi-completion-2026-07/shots/f3-live-and-security-receipt-20260703.txt plus focused receipts f3-password-session-live-20260703.txt, f3-signed-replay-live-20260703.txt, and f3-fhc-post-rotation-forward-proof-20260703.txt.

2026-07-03 - Platform completion D: docs/deck refresh local proof

  • Started D on codex/d-docs-bracket after Q merged. Coordination checks: gh pr list showed only draft PR #77 with empty checks; imsg read +17739974600 --since 2h showed no visible Zak messages. Baseline bun install && bun run verify passed 26 files / 230 tests with bundle assets/index-CdT_flXp.js.
  • Refreshed docs/shots/ from evidence-backed live captures: buyer-market-20260703.png, buyer-leads-20260703.png, buyer-territories-20260703.png, buyer-billing-20260703.png, admin-refund-queue-20260703.png, settings-20260703.png, and admin-supply-20260703.png.
  • Updated docs/walkthrough.html so the deck now shows current buyer parity shots, Payment & Budget cleanup, a live Settings slide, separate Admin supply and Admin refunds slides, and parked-Stripe wording. It no longer claims hosted Stripe checkout is proven while worker secrets/webhook are absent.
  • Rewrote SHARE_WITH_ZAK.md as a current proof-posture ledger: live buyer/admin/settings surfaces, parked Stripe B7 proof, deterministic Comps provider, parked Sequences send-engine, no seller payout/status rails, and the two growth specs as backlog items.
  • Truth pass: docs/content/ROADMAP.md now records D in progress and updates the hard proof gap to 2026-07-03. docs/content/prd/SUPPLY_SIDE.md, CONSENT_MODE_ENHANCED_CONVERSIONS.md, and GOOGLE_ADS_OFFLINE_CONVERSIONS.md were checked and still match the evidence posture.
  • Verification: bun run build:docs passed (10 internal + 2 client docs + index), full bun run verify passed 26 files / 230 tests with bundle assets/index-CdT_flXp.js, and a local rendered walkthrough check at http://127.0.0.1:8801/walkthrough.html showed 19 slides, refreshed screenshots loaded, and zero console errors. Evidence: artifacts/soldi-completion-2026-07/shots/d-docs-refresh-local-receipt-20260703.txt.
  • PR #116 merged at 383d490 after CI passed bun verify and conditional FHC audit. Docs deployed with Worker version f3866350-7cd4-441e-b82f-c3ddbc9b33f4.
  • Live custom-domain proof initially hit stale Cloudflare cache, then clean https://docs.soldi.cc/walkthrough revalidated to the new deck. Browser proof showed 19 slides, current Market/Billing/Settings/Admin supply/Admin refund screenshots, parked-Stripe text, and zero console errors. Evidence: artifacts/soldi-completion-2026-07/shots/d-docs-refresh-live-receipt-20260703.txt.
  • Next: keep the platform-completion loop open on P1/P2 unless Cam accepts the parked Stripe terminal state; do not send Zak wrap text yet.

2026-07-03 - Platform completion Q: Admin field identifiers local fix

  • Started the adversarial Q live pass with a surface matrix that defines unit/integration/programmatic/E2E validation and success criteria for Billing, Settings, Territories, Admin supply/pricing/funnel, FHC ingest, payout posture, and the parked Stripe blocker.
  • Q browser proof on live Admin correctly authenticated as admin@soldi.cc and fetched GET /api/v1/admin/supply-funnel with HTTP 200, but Chrome DevTools surfaced 61 Admin form fields without id or name attributes because every pending lead card repeats a price input.
  • Added stable name attributes to per-lead price inputs, manual lead intake fields, and the batch-discount field. No Admin behavior, pricing math, money movement, or API contracts changed.
  • Verification: focused Admin tests passed 4 files / 17 tests; full bun run verify passed 26 files / 230 tests with bundle assets/index-N5KLlJ4g.js. This fix still needs PR, deploy, and clean live Admin desktop + 375px re-proof before Q can continue.
  • Continued Q on Settings: live /settings persisted demo buyer preferences, but DevTools found 18 unnamed Settings fields plus verbose password warnings because the password inputs were not inside a form. Wrapped Profile, Security, and Buyer Preferences in real submit forms and added stable input/checkbox names, then added the visually hidden autocomplete username field Chrome expects in password-change forms. Focused Settings tests passed 3 files / 11 tests; full bun run verify passed 26 files / 230 tests with bundle assets/index-Bd2PU3o4.js. This Settings fix still needs PR, deploy, and clean live Settings re-proof.
  • Continued Q on Territories: live /territories found unnamed search, weekly-cap, and modal fields before modal proof. Added stable names to the search input, per-order weekly-cap inputs, and the modal Field/Select helpers without changing Standing Order behavior. Focused buyer-screen tests passed 1 file / 5 tests; full bun run verify passed 26 files / 230 tests with bundle assets/index-CdT_flXp.js. This Territories fix still needs PR, deploy, and clean live Territories/modal proof.
  • Continued Q on supply data: remote D1 had 33 legacy/imported leads with market_status='available' but market_price_cents IS NULL. The Market API filters out unpriced rows, but the stored status was still dishonest. Added migration 0021_unpriced_available_back_to_review.sql to move unpriced available rows back to pending_review. This still needs PR, remote D1 migration apply, and D1 proof that unpriced available rows are zero.
  • Q is GREEN after PRs #109-#114. Latest live app proof used Worker version 5eebc802-dc70-4d3c-a3e7-40de88461852 and bundle assets/index-CdT_flXp.js with a matching local/live hash. Browser proof covered Billing, Settings, Territories modal, and Admin supply/pricing/funnel on desktop and/or 375px with zero console messages and unnamed fields. Remote D1 migration 0021_unpriced_available_back_to_review.sql applied; unpriced_available=0. Evidence: artifacts/soldi-completion-2026-07/shots/q-live-qa-receipt-20260703.txt.

2026-07-03 - Platform completion P3/G2: Billing field-name fix

  • Live Billing proof for P3/G2 confirmed the deployed page no longer rendered the fake card selector, auto-reload checkbox, or local editable card rows, and POST /api/v1/payment-methods returned 410 payment_methods_deprecated.
  • Chrome DevTools also surfaced an accessibility issue: the three Billing numeric inputs did not expose stable id or name attributes. Added stable identifiers to Add funds amount, monthly budget, and budget reset day before marking P3/G2 green.
  • PR #107 merged at 65ec9f9; app deployed version 36d92928-d55f-463b-b547-0d63bd22a39d with bundle assets/index-Bc0yNyU9.js. The served JS hash matched local despite HTML/asset cf-cache-status: HIT.
  • Clean live browser re-proof on app.soldi.cc/billing showed no removed decorative controls, stable input identifiers, portal-only card management, and zero render console messages on desktop + strict 375px viewport. Route proof still returns 410 for local POST /api/v1/payment-methods, and /wallet/portal returns the expected fixture portal while Stripe secrets remain absent. Evidence: artifacts/soldi-completion-2026-07/shots/p3-payment-cleanup-live-receipt-20260703.txt. P3/G2 are GREEN.

2026-07-03 - Platform completion P3/G2: payment cleanup local proof

  • Started P3 on codex/p3-payment-cleanup. Billing no longer renders a fake card selector or auto-reload checkbox in Add Funds. Add Funds now takes only an amount, uses the existing demo instant-credit path when Stripe secrets are absent, and uses hosted Checkout when Stripe is configured.
  • Replaced the fake auto-reload control with one honest low-balance nudge derived from the real available wallet balance. Payment Methods now opens Stripe's hosted portal for card management instead of rendering editable local card rows.
  • Deprecated the dead demo-token POST /api/v1/payment-methods route with HTTP 410 payment_methods_deprecated; the route no longer stores fake card data. Checkout/Portal/webhook code remains intact, and no live-mode or money-out rails were added.
  • Verification: focused P3 tests passed 2 files / 3 tests; full bun run verify passed 26 files / 230 tests with bundle assets/index-D7YdzdI1.js. Billing.parts.tsx dropped from 427 to 372 lines. Evidence: artifacts/soldi-completion-2026-07/shots/p3-payment-cleanup-local-receipt-20260703.txt. P3/G2 still need PR, deploy, and live browser proof before GREEN.

2026-07-03 - Platform completion G1: Settings local proof

  • Started G1 on codex/g1-settings-hub. Added a real Settings hub at /settings, reachable from the account menu and command palette. The page has only backed controls: profile name/email, password change, buyer preferences, Payment & Budget link, and sign out.
  • Added authenticated account mutations under /api/v1: PATCH /user/profile enforces email uniqueness; POST /user/password verifies the current password, stores a new PBKDF2 hash, and rotates the signed session cookie; PATCH /user/preferences stores normalized JSON arrays in users.preferred_states and users.preferred_distress_types.
  • Buyer preferences are consumed by the Territories "Add More Territories" flow: saved state/type defaults prefill the Standing Order modal instead of becoming dormant profile data.
  • Verification: focused G1 tests passed 3 files / 11 tests; full bun run verify passed 25 files / 229 tests with bundle assets/index-Dx2mbBwv.js. Evidence: artifacts/soldi-completion-2026-07/shots/g1-settings-local-receipt-20260703.txt.
  • PR #104 merged at d8820ea, then app deployed version e0f655f7-32a5-479a-b05b-cbfff367bf19. Live browser proof registered a disposable buyer, saved profile/email, changed password (old login 401, new login 200), saved TX + Probate preferences, proved the Territories modal defaulted to Statewide TX / Probate, and captured zero console errors on desktop + 375px. Remote D1 proof shows the updated user row. Evidence: artifacts/soldi-completion-2026-07/shots/g1-settings-live-receipt-20260703.txt. G1 is GREEN.

2026-07-03 - Platform completion A4 GREEN: seller payouts spec-only

  • Closed A4 as a spec-only predicate. docs/content/prd/SUPPLY_SIDE.md section 7 documents seller payouts as PENDING_CAM and explicitly forbids Stripe Connect, bank onboarding, identity, payouts, refund-to-card, or money-out tables in this program.
  • Tracker PENDING_CAM ask #2 keeps Decision #0 open: pure lead marketplace vs principal/committed-offer posture gates seller payout semantics.
  • Verification grep over app/migrations, app/worker, and app/src found no seller payout, Stripe Connect account, bank-account, identity, external-account, or money-out implementation. The only app-side hit was a generic Transactions styling comment. Evidence: artifacts/soldi-completion-2026-07/shots/a4-payout-spec-receipt-20260703.txt.

2026-07-03 - Platform completion A3 GREEN: Admin supply funnel live proof

  • PR #101 merged at c9c4b91, adding GET /api/v1/admin/supply-funnel plus the Admin supply-funnel panel. The route returns captured/scored/priced/reviewed/listed/sold-or-expired counts and recent lead drill-in rows with source, consent, quality, review status, current price, and price history.
  • App deployed version 72448e73-1d5b-454e-a852-be64b818bbd4. Live API proof as admin@soldi.cc returned 52 captured, 52 scored, 15 priced, 2 reviewed, 0 listed, and 13 sold/expired leads; unauthenticated access returned 401. Remote D1 aggregate query matched those counts.
  • Chrome DevTools browser proof logged into app.soldi.cc/admin as admin and captured the new Supply funnel section plus drill-in rows and price history. Screenshot: artifacts/soldi-completion-2026-07/shots/a3-supply-funnel-admin-20260703.png. Receipt: artifacts/soldi-completion-2026-07/shots/a3-live-supply-funnel-receipt-20260703.txt. A3 is GREEN.

2026-07-03 - Platform completion A3: Admin supply funnel local proof

  • Started A3 on codex/a3-supply-funnel. Added GET /api/v1/admin/supply-funnel in a separate route module so admin-leads.ts stays below the file-size limit. The endpoint returns captured/scored/priced/reviewed/listed/sold-or-expired counts plus recent lead drill-in rows with source, consent evidence, review status, current price, and price history from audit_log.
  • Added a compact Admin supply-funnel panel above manual intake: lifecycle tiles and a wide operational table. The UI stays admin-only and does not introduce seller-facing promises, testimonials, or public status language.
  • Seller-facing status remains parked in docs/content/prd/SUPPLY_SIDE.md: future tokenized neutral states only, with payout/offer language blocked until Decision #0 is resolved.
  • Verification: focused A3 tests passed 2 files / 7 tests; root bun run verify passed 23 files / 222 tests with bundle assets/index-CWo7ymPN.js. A3 still needs PR, deploy, and live browser/API/D1 proof before GREEN.

2026-07-03 - Platform completion A2 GREEN: table-backed Admin supply proof

  • PR #99 merged at 685083e, adding lead_price_bands, table-backed price resolution, Admin manual-intake integration, and FHC ingest default pricing while keeping unpriced bridge leads in pending_review.
  • Remote D1 migration 0020_lead_price_bands.sql applied successfully; lead_price_bands contains 10 rows and PB_IL_COOK_PRE_FORECLOSURE_HIGH prices at 25000 cents. App deployed version fdc8a493-7412-4d46-abd6-2181259a3e8a.
  • Live proof as admin@soldi.cc created synthetic lead L_MR4Q0GW8_68C114C7F56DD8EC3B3E9334 without an explicit price; API returned marketPriceCents=25000, marketStatus=pending_review, and priceBandId=PB_IL_COOK_PRE_FORECLOSURE_HIGH. Admin then saved override price 17000, approved to Market, verified Market visibility at 17000, batch-discounted to 15300, verified Market visibility at 15300, and rejected the proof lead for cleanup.
  • Remote D1 proof shows the lead row has price_band_id=PB_IL_COOK_PRE_FORECLOSURE_HIGH and price_band_source=lead_price_bands; audit rows exist for lead.manual_create, lead.price_update, lead.approve, lead.discount_apply, and cleanup lead.reject. Evidence: artifacts/soldi-completion-2026-07/shots/a2-table-bands-live-receipt-20260703.txt. A2 is GREEN.

2026-07-03 - Platform completion A2: table-backed price bands correction

  • A2 fidelity audit found the prior live proof exercised Admin manual intake, price override, approve-to-Market, batch discount, and audit rows, but the default "price band" came from an in-code formula rather than the goal-required table-backed bands.
  • Added app/migrations/0020_lead_price_bands.sql with active state/metro/distress/default bands and seeded defaults. Added app/worker/price-bands.ts to resolve the best matching band by state, metro, distress type, value range, and equity range, with the old deterministic formula retained only as a migration-missing fallback.
  • Admin manual intake now uses the table resolver when an operator does not provide marketPriceCents; FHC ingest also applies a default band price when the bridge omits price, while keeping those leads pending_review and out of Standing Order auto-allocation until Admin review.
  • Verification: focused route tests passed 33 tests / 74 assertions; root bun run verify passed 22 files / 221 tests with bundle assets/index-DGvE8OuP.js; bun run build:docs and git diff --check passed. Migration SQL applied cleanly in an in-memory Bun SQLite check and seeded 10 bands; local Wrangler migration execution was SIGKILLed before output, so remote migration still needs direct proof before A2 returns to GREEN.

2026-07-03 - Platform completion A2: Admin supply controls local-complete

  • Continued A2 on codex/admin-supply-batch. Added app/worker/routes/admin-supply.ts for Admin-only manual lead intake and batch discounts, mounted under /api/v1/admin/leads/*.
  • Manual intake inserts a lead, consent attestation, and audit row in one D1 batch. If an override price is absent, it applies a deterministic price band from estimated value, equity, and distress type; every price remains integer cents and the lead stays pending_review until reviewed.
  • Batch discount accepts up to 50 lead IDs, skips sold/rejected/clawed-back/unpriced rows, updates priceable rows, and writes one lead.discount_apply audit row per update.
  • Admin UI now includes a compact manual intake panel plus batch discount control above the review queue, alongside the previously landed per-lead price save and safe approve-to-available rail.
  • Verification: focused Admin tests passed 3 files / 16 tests; bun run verify passed 22 files / 221 tests with bundle assets/index-DGvE8OuP.js; bun run build:docs and git diff --check passed; touched files remain <400 lines. A2 still needs PR, deploy, and live proof before GREEN.

2026-07-03 - Platform completion A2: Admin pricing controls local proof

  • Started A2 on codex/admin-pricing-controls. Added an audited admin pricing mutation for leads (POST /api/v1/admin/leads/:id/pricing) that accepts integer-cent marketPriceCents, rejects sold/rejected/clawed-back leads, updates price fields, and writes lead.price_update in the same D1 batch.
  • Admin approval now only flips a lead to market_status='available' when the lead already has a non-null market price. Unpriced FHC bridge leads can still be reviewed, but they remain out of Market until priced.
  • The Admin lead review card now includes a compact price input + Save price action and disables Approve for unpriced rows. UI polish was kept inside existing Admin card/button/tokens; the local .claude Workflow DSL is not directly runnable from this Codex tool surface, so the mandatory make-it-sexy/make-it-simpler pass was applied manually against the touched Admin files.
  • Verification: focused Admin tests passed 2 files / 13 tests; bun run verify passed 21 files / 218 tests with bundle assets/index-CwRNFhJm.js; bun run build:docs and git diff --check passed. A2 remains IN_PROGRESS because manual add-lead, price bands, discount batch, deploy, and live proof are not in this slice.

2026-07-03 - Platform completion A1: FHC ingest bridge local proof

  • Built the first FHC -> Soldi bridge slice on codex/fhc-ingest-bridge: app/worker/routes/ingest.ts now accepts omitted marketPriceCents and stores those leads as market_status='pending_review', skipping Standing Order auto-allocation until Admin pricing/review work makes the lead marketable.
  • Added the FHC-side mapper/signer (sites/fhc-pages/src/soldi-ingest.ts) and wired complete, consented offer requests to post signed JSON to https://app.soldi.cc/api/v1/ingest/leads when FHC_INGEST_SECRET is present. Partial/no-consent records remain in the existing KV/email flow.
  • Added a dry-run-first KV backlog drain (sites/fhc-pages/scripts/drain-leads-to-soldi.ts) using soldi-drain:<lead-key> markers for idempotency. Local proof is captured in artifacts/soldi-completion-2026-07/shots/a1-local-bridge-receipt-20260703.txt: focused ingest tests passed 31 tests, FHC mapper tests passed 3 tests, drain --limit=0 smoke passed, root bun run verify passed 21 files / 215 tests, and FHC build/audit generated 539 pages with 0 blockers.
  • A1 is now GREEN. PR #95 merged at fbcdab4; matching FHC_INGEST_SECRET is set on app + FHC workers; app deployed version a02eceff-0d69-4662-8bae-18711826889f; FHC uploaded version a419b369-1923-4cfc-be56-355c272ace2e (custom-route update still exits with token permission code 10000 after upload, but the live custom domain served the worker). Live URL-encoded FHC submissions created Soldi pending_review rows with market_price_cents=null, Admin pending queue returned them, and the cutoff backlog apply forwarded 2 pre-bridge records while marking 20 pre-bridge records with 0 remaining forwardable. Redacted evidence: artifacts/soldi-completion-2026-07/shots/a1-live-bridge-receipt-20260703.txt.

2026-07-03 - Platform completion A0: supply-side PRD (PR #93)

  • Added docs/content/prd/SUPPLY_SIDE.md, the spec bridge between Fair Home Cash capture and Soldi supply/admin work. It reconciles the live HMAC ingest route, current Admin review console, .wrkts/supplier-admin prior art, and LEAD_FUNNEL.md Decision #0.
  • Recommended defaults are now explicit: FHC bridge plus admin manual intake, price bands plus admin override, admin-first supply visibility, and seller payouts as spec-only/PENDING_CAM until Cam chooses pure marketplace vs principal/committed-offer posture.
  • Registered the PRD in the docs build as /prd-supply-side. No runtime app/FHC behavior changed in this slice; FHC_INGEST_SECRET, bridge forwarding, migrations, and live proof are A1/A2 work. Verification: local bun run build:docs passed 10 internal + 2 client docs, local bun run verify passed 21 files / 213 tests, and GitHub CI passed on PR #93.

2026-07-02 — FHC: stealth hero restored per founders' locked playbook (PR #90)

  • Zak's PR #90 restored the bold "We Buy Houses in {state}. Cash. As-Is." hero on state/city/ homepage — per the pre-existing locked decision (internal/legal/DECISIONS-LOCKED.md, 6/26: "Bold 'We Buy Houses For Cash' hero stays") and Terms §2 DRAFT, which is engineered for it (lead-gen disclosure + the principal is an active cash buyer who may purchase-and-assign). Provenance note: this is the founders' documented risk call on DRAFT terms — counsel has not yet answered the brief; the PR's "attorney-approved" framing was corrected in the merge.
  • Hard lines all held (verified live): fabrication bans stay in the audit and pages (no fake testimonials/stats/track record), "flat marketing fee" + "independent cash buyers" disclosure copy stays visible, TCPA consent intact, calculators + non-IL guides remain educational. Conflict with #89 resolved (audit regex → fabrication-only). Deployed + live-verified.
  • Follow-up in the same push: ES i18n dict brought into lockstep with #90's EN changes (how1p, finalP/finalCta — "Compramos casas…" now mirrors the EN stealth voice).

2026-07-02 — FHC: nationwide funnel in honest connector voice (Option 1)

  • Founders aligned (texts + session): ship #86's nationwide funnel, cut the false buyer-identity copy. Landed as one integration branch: #86 (guides + i18n + flips) + #87 (two-way audit + educational hardening) + a same-day connector-voice rewrite across state/city/IL templates, meta/OG, JSON-LD, and the EN/ES dictionaries (consent line now translated). Fabrications deleted from rendered surfaces: fake testimonials w/ Google/BBB attributions, "480 homes / $96M+" track record, activity toasts, foundingDate 2019, first-person purchase histories in hand-written content. No guarantees or 24-hour offer promises anywhere (no buyer SLA exists).
  • Schema: RealEstateAgent → LocalBusiness; honest Organization/Service descriptions; educational pages still emit no business/offer nodes. Audit now ENFORCES the honest voice sitewide (three layers: visible / JSON-LD / meta+OG, EN+ES) + requires the "independent cash buyers" disclosure anchor on funnel pages; the old stealth-voice rule (which required the false voice) is gone. First enforcement run caught 917 violations; driven to zero.
  • Carve-outs pending counsel (MARS / §2945-family): 50 state calculators + non-IL guides stay zero-solicitation educational. 539 pages built, audit LAUNCH READY (0 blockers, 528 audited).

2026-07-02 — FHC: PR #86 triage + educational-posture hardening

  • Zak's PR #86 flips transactional = true on all 50 state pages + the homepage before counsel has answered the expansion brief. Five-lens Workflow review (claims / statutes / content / tech / SEO) synthesized into artifacts/soldi-fhc-ship-2026-06/PR86_TRIAGE.md: a 16-finding triage table, Paths A/B/C, and 7 new counsel questions (incl. MARS/Reg O). Recommendation: A → C — hold the flip, make IL-only actually true, rewrite to honest connector voice, then expand state-by-state as counsel clears. Content lens: only 49 of the 196 new guides (foreclosure) are unique statute-driven bodies; the other 147 are token-swap near-duplicates.
  • Hardening landed on triage/pr86-proposal: two-way audit (educational pages now FORBID funnel markers and solicitation across visible text / JSON-LD / meta+OG — the first run surfaced 101 blockers on main), guide CTA strip, educational FAQ-schema mirror + RealEstateAgent/Service/ $0-Offer nodes dropped from educational @graphs, all 50 calculator funnels gated (offer box, soft capture with auto-consent=on, sticky + exit popups), homepage/where-we-buy fully educational, non-IL foreclosure-guide titles de-solicited.
  • Verification: 343 pages rebuilt; bun run audit LAUNCH READY (0 blockers) under the hardened gate; IL funnel surfaces unchanged (offer form + RealEstateAgent verified present on IL pages). Still open: 204 city pages remain ungated (policy-module decision), Path C voice rewrite, guide-merge decision on #86.

2026-07-01 — Live C2 admin refund re-proof

Re-proved C2 against hosted app.soldi.cc on a fresh branch/worktree. Baseline bun install && bun run verify passed with 21 test files / 211 tests and Vite build index-BzIT9cCX.js; wrangler whoami confirmed the Cloudflare token is scoped to account 2fb55b3d56fa4a0cb926515ecd0b1a6f.

The dedicated admin@soldi.cc account already existed from the earlier live signup proof, so a fresh same-email registration would be duplicate-blocked rather than a valid new signup. D1 proof still shows the admin user row, the signup-bonus wallet transaction, and admin=1 after the authorized idempotent elevation command.

As demo@soldi.cc, the browser created a real product touchpoint on PF_SEED_02 through the live Pipeline stage-change route, then submitted refund RR_MR2TUOLY_64BD4671E40942561A9697EC for L_MIA_TAXLIEN_05 through RefundModal. As admin@soldi.cc, the Admin queue showed that fresh request plus seeded RR_MKT_03; approval credited the demo wallet by 21000 cents, moved balance to -29400, marked the refund approved, and marked PF_SEED_02 refunded.

Evidence is under artifacts/soldi-fhc-ship-2026-06/shots/c2-refresh-*: Admin registration/elevation D1 proof, buyer stage-touchpoint proof, RefundModal and pending-row proof, Admin queue before/after screenshots, approval JSON, D1 wallet proof, buyer Refund Status screenshot/API proof, replay 409 proof, and non-admin 403 proof.

Next: C2 remains green. B7 remains blocked on Stripe worker secrets plus dashboard webhook proof; do not deploy sites/fhc-pages.


2026-07-01 — FHC attorney brief for nationwide expansion questions

Added artifacts/soldi-fhc-ship-2026-06/ATTORNEY_BRIEF_FHC_EXPANSION.md, a counsel-facing brief that freezes the current FHC fact pattern: Fair Home Cash LLC as the Illinois consumer entity, nationwide educational calculator/statute pages, the PR #73 Illinois-only transactional funnel gate, no non-IL PII capture, TCPA/TrustedForm on the IL form, and the privacy draft's flat per-lead lead-generation posture. The brief asks counsel for three concrete sign-offs: direct-buyer state expansion requirements, lead-generation/broker-license posture for flat buyer-paid marketing fees, and the consent/privacy/schema disclosure stack. It also includes the requested nine-state appendix from sites/fhc-pages/data/foreclosure-rules.ts, with solicitation-statute items explicitly marked verify.

Verification: bun install && bun run verify passed from the isolated .wrkts/attorney-brief worktree before final commit work: 21 test files / 211 tests passed + Vite build index-BzIT9cCX.js. No deploy was run; this was a docs-only counsel-prep lane. Next up: counsel returns the state matrix and approved disclosure/fee structure before any non-Illinois funnel capture is enabled.


2026-07-02 — Fixed the deck's demo login: navigations never reached the worker

The walkthrough deck's ?demo=1 auto-login has been silently broken in production: with not_found_handling: single-page-application, the static-asset layer serves index.html for any browser NAVIGATION (Sec-Fetch-Mode: navigate) to a non-asset path without invoking the worker — so the demo middleware never ran and deck iframes landed on /login. Proven side-by-side: plain curl to /api/v1/auth/demo → worker 302; navigate-header curl to the same URL → cached SPA HTML (cf-cache-status: HIT). Two-part fix, both merged + deployed: PR #83 adds a canonical GET /api/v1/auth/demo?next=<path> (Cache-Control: no-store, open-redirect-guarded + unit-tested; walkthrough liveSrc now uses it), and PR #84 sets run_worker_first: ["/api/*", "/webhooks/*"] so the worker owns API paths for all request modes. Browser proof: navigating the demo URL lands authed on /market as demo@soldi.cc, zero console errors — shots/demo-login-fixed-market-authed-20260702.png. Also this session: parity-safe polish pass over 18 UI files (PR #82, 213 tests green) merged + deployed.

2026-07-01 — Landed Zak's PR #73: nationwide FHC calculators + guides (IL-gated funnel)

Merged Zak's feat/fhc-nationwide-calculators-guides (#73) as-is plus two review commits pushed to his branch (f509d7c, e6cb959): swapped the hardcoded fasthomecash.us canonical/og/JSON-LD/mailto references for config.domain on all 50 generated state calculator pages, extended audit.ts per-page coverage to those pages (previously excluded by the legacy IL-calculator filter), removed the unattributed exit-popup testimonial, and gated the transactional funnel (We-Buy-Houses hero, lead form, phone CTAs, exit popup) to Illinois only — non-IL state pages are educational (calculator + statutes + market data + sources) pending counsel on foreclosure-consultant statutes. PR #74 fixed CI to build FHC before auditing and wired sites/fhc-pages into root Bun workspaces so clean installs resolve eta. Verification: build 343 pages, audit LAUNCH READY, fasthomecash 0 in source+dist, firewall \bsoldi\b 0, CA page has 0 funnel markers vs IL 14; both GitHub checks green pre-merge. NOT yet deployed — bun run deploy:fhc awaits Cam's approval. Attorney follow-ups: nationwide funnel expansion state-by-state; the pre-existing nationwide areaServed schema question.


2026-07-01 — Closeout hardening: CI, Wrangler 4, docs screenshots, growth specs

Added a GitHub Actions CI workflow for every pull request into main: one job runs bun install && bun run verify, and a second reported job runs the FHC audit only when sites/fhc-pages/** changes. This closes the gap where this session's PRs merged with an empty statusCheckRollup. PR #70 landed the workflow, then dummy PR #71 proved the checks report on GitHub: bun verify and FHC audit when changed both completed SUCCESS; #71 was closed unmerged.

Aligned deploy tooling on repo-pinned Wrangler 4 by upgrading root/app/FHC manifests and lockfiles to Wrangler 4.106.0. The FHC workspace also had a tracked broken self-referential node_modules symlink; it was removed so cd sites/fhc-pages && bun install can work normally in CI.

Refreshed docs/shots/ from live app.soldi.cc after the buyer/admin parity work: Market table, Leads, Territories, Payment & Budget, and Admin refund queue. The walkthrough now marks Payment & Budget and Admin refund queue as live where evidence supports it, while keeping Stripe checkout/webhook proof explicitly pending. Zak's two parked growth asks are now backlog PRDs: Consent Mode v2 / enhanced conversions, and Google Ads offline conversion imports keyed on lead-quality outcomes.

Verification: bun run verify -> 21 test files / 211 tests passed + Vite build index-BzIT9cCX.js; bun run build:docs -> 9 internal + 2 client docs + index; bun run build:fhc -> 288 pages generated; FHC audit -> 0 blockers. Wrangler 4 dry-runs passed for app, docs, previews, and FHC; receipts are under artifacts/soldi-fhc-ship-2026-06/shots/closeout-wrangler4-*.

Still blocked: B7 is not green. bunx wrangler@4 secret list --config app/wrangler.jsonc still shows only SESSION_SECRET, so Text 2 and MVP_SHIPPED_PROOF_DELIVERED remain gated on Cam setting STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, and proving the Stripe dashboard webhook.

2026-07-01 — Adversarial live QA for buyer parity, preview scrub, and D1 parity

Ran the retro-style hosted QA pass against app.soldi.cc, not local. Desktop and 375px mobile browser proof covered /market, /leads, and /territories: distress filters changed the live lead rows, the Standing Order banner and Just claimed ticker rendered, owned-lead rows opened the dossier drawer, and the Territory bid stepper fired a live PUT /api/v1/standing-orders/:id and persisted across reload. The pass found real issues: the Market "map" was a decorative fake map despite no map provider being configured, the Territories table had no weekly-cap edit control, and Market could log a console error for an abort-like fetch during route changes.

Patched the findings in the buyer screens. Market Map is now an honest no-provider "Map view coming soon" state with the live lead list still usable for buying, Territories rows now have weekly-cap decrement/input/increment controls wired through the existing integer/Zod PUT /standing-orders/:id route, and abort-like Market/Scoreboard route-change fetches no longer log console errors.

Verification: Baseline bun install && bun run verify -> 21 test files / 210 tests passed + Vite build index-BFVM8eKn.js. Focused post-fix cd app && bun run test -- src/pages/BuyerScreens.test.tsx -> 4 pass. Full post-fix bun run verify -> 21 test files / 211 tests passed + Vite build index-BzIT9cCX.js; bun run build:docs also passed. First post-deploy browser proof on app Worker version 4c9bc62c-c444-41fa-8354-adbb2091374a confirmed the Market coming-soon map, dossier drawer, and persisted weekly-cap edit, then exposed one remaining ScoreboardBar route-change console error; that cleanup is included here. Remote D1 ledger query shows migrations 0001 through 0019_market_portfolio_stages.sql applied. Served preview https://preview.soldi.cc/mkt-d64dc6e2/ hash matches both local twin files; served-HTML PII audit found only reserved 555-010-01xx fixtures and @example.com emails, with no non-example emails, street addresses, or proper-name hits. Evidence is under artifacts/soldi-fhc-ship-2026-06/shots/liveqa-*.

Final merge/deploy proof: PR #68 merged at 0c416d7, app Worker version 61ce08a4-0fa6-4596-b859-45fae1a99c4c deployed assets/index-BzIT9cCX.js, and docs Worker version 7b0a6013-e514-4da4-a4ce-50bdb715975c deployed the updated log. The final hosted browser pass on app.soldi.cc desktop and 375px mobile recorded consoleErrors: [] and pageErrors: []: Market filters changed rows 3 -> 2, the Map state had 0 fake pins and a coming-soon message, Leads rows opened the dossier drawer, and Territories bid + weekly-cap controls both sent live PUT /api/v1/standing-orders/SO_MKT_01 200 responses and persisted through reload. Evidence is under artifacts/soldi-fhc-ship-2026-06/shots/liveqa-final-*.

Next: B7 remains pending on Stripe worker secrets plus dashboard webhook proof. Do not send Text 2 until B7 is green and C1 can be re-run as Stripe-funded instead of fixture-funded.

2026-07-01 — Live C2 admin refund proof

Created the dedicated production admin@soldi.cc account through the normal live registration UI, after adding an explicit .gitignore rule for artifacts/soldi-fhc-ship-2026-06/.admin-credentials.local. The generated password is stored only in that ignored local file and should be rotated by Cam. Registration proof covered /auth/register 201, browser /auth/me, the remote D1 user row, and the signup bonus wallet transaction before the account was elevated to admin=1.

Then proved C2 live end to end. As demo@soldi.cc, the browser RefundModal submitted pending refund RR_MR2MW1FT_9EF23ACE815B8065666DAA7D for PF_SEED_04 / L_ATL_PREFCL_10; the request cleared the touchpoint gate from existing portfolio actions. As admin@soldi.cc, the live Admin queue showed that fresh request plus seeded RR_MKT_03, and approving the fresh request credited the buyer wallet by 11100 cents, changed the refund to approved, and marked the portfolio refunded.

Verification: bun install && bun run verify -> 21 test files / 210 tests passed + Vite build index-BFVM8eKn.js. Evidence is under artifacts/soldi-fhc-ship-2026-06/shots/: registration screenshots/JSON, c2-admin-registration-d1-proof-20260701.txt, c2-admin-elevation-d1-proof-20260701.txt, c2-demo-refund-request-browser-proof-20260701.json, live Admin queue screenshots before/after approval, c2-approved-refund-wallet-d1-proof-20260701.txt, and c2-demo-refund-status-approved-20260701.png. Idempotency/authorization checks passed live: replaying the approval returned 409 refund_already_decided, and authenticated demo GET /api/v1/admin/refunds?status=pending returned 403 forbidden.

Next: B7 remains pending on Stripe worker secrets plus dashboard webhook proof. Do not send Text 2 until B7 is green and C1 can be re-run as Stripe-funded instead of fixture-funded.

2026-07-01 — Walkthrough buyer-screen refresh

Refreshed the docs walkthrough around the buyer-facing screens that changed in the mockup parity pass. The old Auction Floor slide is now a live Buyer Market slide with the current masked fixed-price lead table framing, and the deck now includes dedicated My Leads and Territories slides using the current browser-captured screenshots from the deployed buyer parity work. This keeps /walkthrough from describing the old card grid or hiding the new Leads and Territories surfaces.

Verification: bun run build:docs -> 7 internal + 2 client docs + index. Local generated-docs browser QA on http://127.0.0.1:8801/walkthrough.html confirmed the Market slide renders, Leads uses /shots/buyer-leads-20260701.png, and Territories uses /shots/buyer-territories-20260701.png; proof screenshot: artifacts/soldi-fhc-ship-2026-06/shots/walkthrough-buyer-slides-local-20260701.png.

Next: deploy docs after merge, then leave the remaining MVP terminal state on B7 Stripe secrets/webhook and the production admin user needed for live C2 approval proof.

2026-07-01 — Admin refund queue readiness for C2

Added the missing Admin refund review surface around the existing refund decision route. Admins can now fetch GET /api/v1/admin/refunds?status=..., see pending and recently resolved refund requests with buyer/lead context, amount, reason/detail, touchpoint count, and status, then approve or decline from the Admin page through the existing POST /admin/refunds/:id/decide path. This does not elevate any production user or complete live C2 proof; it makes the queue ready for the seeded pending RR_MKT_03 once a real admin account exists.

Verification: PR #63 merged at af1fd63; cd app && bun run test -- worker/admin-refunds.test.ts src/pages/Admin.test.tsx -> 9 pass; bun run verify -> 21 test files / 210 tests passed + Vite production build index-BFVM8eKn.js. Local browser QA used http://localhost:8787/admin?demo=1 with only the local Miniflare demo user elevated to admin; screenshots saved at artifacts/soldi-fhc-ship-2026-06/shots/c2-admin-refund-queue-local-20260701.png and artifacts/soldi-fhc-ship-2026-06/shots/c2-admin-refund-queue-mobile-local-20260701.png. Browser proof saw Admin, RR_MKT_03, Approve, and Decline visible with no console errors. Deploy proof: app Worker version a5c6dc40-9dc2-4fbc-be17-f5bc40673e68; docs Worker version 0ac5abbd-23e8-4bea-bf65-b652547385a0; app.soldi.cc serves assets/index-BFVM8eKn.js; /api/v1/health returned 200; unauthenticated /api/v1/admin/refunds?status=pending returned 401; docs /build-log and /roadmap render the C2 readiness entry.

Next: keep C2 as partial until production has an admin user. Then prove approve/decline live against RR_MKT_03 or a fresh refund and confirm the buyer Refund Status/wallet ledger update.

2026-07-01 — Buyer mockup parity: Market, Leads, Territories + testing plan

Ported the remaining old buyer app screens to the reviewed previews/marketplace-client.html mockup while keeping the live data contracts intact. Market now renders the masked lead table with distress tabs, Grid/Map toggle, Standing Order banner, "Just claimed" ticker, masked address copy, and the existing fetchMarketLeads / buyMarketLead flow. My Leads now points to a dedicated /leads owned-leads table instead of the Pipeline kanban; the table uses the existing pipeline/lead ownership APIs and keeps row click wired to the lead dossier drawer. Territories now renders a PL-style standing-order table with real bid steppers through updateStandingOrder, search, pagination, row removal, and a three-section Add More Territories modal.

Also added docs/content/TESTING_PLAN.md and published it through the docs build as /testing-plan.html, defining unit, integration, programmatic, and e2e success criteria for app, docs, previews, and FHC surfaces.

Verification: PR #61 merged at e528696; bun install -> no changes; cd app && bun run test -- src/pages/BuyerScreens.test.tsx worker/pipeline.test.ts -> 21 pass; bun run verify -> 21 test files / 208 tests passed + Vite production build index--WTSuKDJ.js; bun run build:docs -> 7 internal + 2 client docs. Local browser QA used http://localhost:8787 after applying local D1 migrations and demo login, with desktop/mobile screenshots saved under artifacts/soldi-fhc-ship-2026-06/shots/buyer-*20260701.png for Market, Market map, Leads, Leads drawer, Territories, Territories modal, and mobile views. Deploy proof: app Worker version df2009c1-0bef-4c5f-ba85-0e24f2b486b6; docs Worker version d9e4c2fc-d983-4777-ab69-78c9ab5892fe; app.soldi.cc serves assets/index--WTSuKDJ.js; /api/v1/health returned 200; docs.soldi.cc/testing-plan, /build-log, and /roadmap render the new entries.

Next: refresh the live walkthrough screenshots, then return to the hard MVP blockers: Stripe worker secrets/dashboard webhook for B7 and a live admin user for C2 refund approval proof.

2026-07-01 — Market buy now reaches Pipeline + C1 fixture proof

Finished the C1 browser pass for fixed-price Market buying and fixed the gap it exposed. The demo buyer bought L_MKT_09 after a no-secret fixture wallet top-up; D1 had the portfolio and wallet charge, and GET /leads/L_MKT_09 returned buyer-only seller contact data, but /pipeline did not show the lead because POST /market/leads/:id/buy created portfolios without the matching portfolio_stages row. Market purchases now create an initial new stage row, and migration 0019_market_portfolio_stages.sql backfills any existing portfolios missing one.

Verification: cd app && bun run test -- worker/market.test.ts -> 1 pass; bun run verify -> 20 test files / 204 tests passed + Vite production build index-s8UTI49q.js; bunx wrangler@4 deploy --config app/wrangler.jsonc --dry-run passed; remote D1 migration 0019_market_portfolio_stages.sql applied; app Worker deployed as 29899a5d-3834-4b4d-946a-49f9d9d62b2a; live health 200 and app.soldi.cc serves assets/index-s8UTI49q.js. Browser proof as demo@soldi.cc showed /api/v1/pipeline?filter=all includes L_MKT_09 in stage new and captured artifacts/soldi-fhc-ship-2026-06/shots/c1-pipeline-lead-contact-L_MKT_09-20260701.png with seller contact details.

Next: C1 is green only as fixture-funded proof. B7 still needs Stripe worker secrets + dashboard webhook before claiming real Stripe-funded checkout, and C2 still needs a live admin account for refund approval proof.

2026-07-01 — Auction settlement C3 audit + D1 timestamp fix

Verified the cron settlement path against the MVP C3 predicate and fixed one subtle D1 time bug. settleDueAuctions now selects due auctions with datetime(end_time) <= datetime(?) instead of raw string comparison, so D1's space-separated datetime() values cannot sort as due before their actual time. Added worker-level settlement tests covering unsold marking, winner hold-to-charge conversion, wallet charge ledger rows, portfolio creation, floor sold event emission, and displaced-bidder hold release at bid time via releaseOutbidLeader.

Verification: cd app && bun run test -- worker/settlement.test.ts -> 10 pass; bun run verify -> 19 test files / 203 tests passed + Vite production build index-BgL_jj_a.js. No deck screenshots were refreshed because this patch changes cron/query correctness only, not a rendered UI surface.

Next: ship the C3 patch; B7 remains blocked on Stripe worker secrets + dashboard webhook, and live C2 proof still needs an admin account.

2026-07-01 — Billing Add funds now falls through to Stripe Checkout test mode

Wired the Billing page's Add funds flow to the real wallet checkout contract without touching live Stripe. The client still calls POST /payments/deposit first; demo/local mode keeps the existing instant-credit path, while Stripe-configured mode branches only on 409 stripe_checkout_required and then calls POST /wallet/checkout. The returned deterministic fixture/stub session is shown in Billing as a Stripe test checkout state, with navigation restricted to same-origin relative URLs. The old hand-entered Add card form was removed from the visible Billing UI so card collection is no longer fabricated on-page.

Verification: bun test src/lib/__tests__/payments.test.ts -> 2 pass; bun run typecheck clean; bun run verify -> 16 test files / 182 tests passed + Vite production build; grep -rn "api.stripe.com" app/src app/worker returned no matches; git diff --check clean. Docs build was attempted after the walkthrough copy update, but this isolated worktree is missing the declared marked package and the prompt forbids bun install, so bun run build:docs is deferred until dependencies are available.

Next: owner-approved deploy only when the integrated app branch is ready; subscriptions/tiers remain product design work.

2026-06-30 — Visible per-state statute strip on city pages + LIVE

Shipped audit Fix #2 from the #39 growth research (B2 "answer-first / quotable data"): a visible per-state legal-facts strip on every city page, rendered from data/states.ts (foreclosure process, typical timeline, redemption period, effective property-tax rate + national rank, transfer-tax note, and a § Key legal fact callout). It surfaces the per-state statute data that was already the site's real moat but invisible to readers + answer engines. On-brand (Fraunces serif, terracotta accent, soft-shadow card); on IL pages it renders above the existing .aeo-il cost module. Additive, +57 lines to template/city-page.eta, zero page loss.

Verification: bun run build:fhc → 357 pages, 0 errors; bun run auditLAUNCH READY, 0 blockers; strip live on a non-IL page (Phoenix: "Non-judicial · Redemption period · Effective property tax") and an IL page (Chicago: statute strip + .aeo-il both); brand firewall 0 soldi (only the whitelisted "Soldiers Field" landmark on rochester-mn). Squash-merged #40 → main (2f33553); bun run deploy:fhc (worker uploaded clean; expected exit-1 on the domain-attach, apex already bound) — confirmed live via curl on fairhomecash.com (the brand-new module serving proves the deploy landed regardless of the stale deployments list record).

Also confirmed this pass: llms.txt (B7) is already generated + live (generateLlmsTxt() in build.ts:773/llms.txt 200) — no new work; a redundant static/llms.txt I'd started was reverted. Corrected the sites/fhc-pages/CLAUDE.md moat line (real moat = hand-written per-city Local Insight + per-state statute data + the IL AEO calculator/module; computeVariant() only reword-rotates the hero, cosmetic). /where-we-buy confirmed 200 (the llms.txt link is valid). PR #3 (Comps V2) stays parked for separate review.

Next: Fix #1 (197-page scaffolding diversify — regenerates live content, awaits Cam's nod); the Soldi app's stale "Floor" → Market/Shop framing bridge (surfaced by the overnight spec loop); [NEEDS CAM] human plays (GBP, Reddit, digital PR, YouTube). RED-tier tactics remain off-limits.


2026-06-27 — Zak's IL-AEO layer integrated onto main SEO foundation + LIVE

Combined Zak's IL-AEO branch (zak/fhc-nj-fixes) additively onto main's SEO foundation — a confirmed joint call (no SEO removed; both bodies of work ship whole). Zak's branch was cut from an old base predating the @graph/situation/sitemap layer, so a raw merge read as destructive; hand-ported in an isolated worktree instead (11-agent ultracode workflow: 3 implementers → gate → 5 adversarial reviewers → repair → re-gate). Live on the apex:

  • Zak's 10 AEO features — IL foreclosure-deadline calculator; IL cash-vs-agent .aeo-il module (IL-gated, sourced figures + estimated-cost disclaimer); 4 deep state-level IL situation pages (buildIlSituationPages, coexisting with main's ~70 broad situation×geo via rename to il-situations.ts/il-situation-page.eta — disjoint routes, zero collision); one-question wizard; mobile sticky/cta bars; withSecurityHeaders; 400/hasSignal guards; click-to-call (773) 997-4600; IL tax fixes (2.07%, Cook $0.25 / Chicago $5.25) + lead-alert IL field union.
  • Interlinked IL geo pages ↔ the 4 deep pages + calculator (depth feeds breadth's authority).
  • Stripped a LIVE FTC fabricationrecentPurchases "Homes we bought this month" cards (invented transactions + stock photos) on Chicago/FL, pre-existing in main, now removed.
  • Terms arbitration venue → Cook County, IL (provisional + TODO(legal), #30).

Verification: audit LAUNCH READY (368 pages, zero page loss); 6 reviewer blockers fixed + independently re-verified; kill-greps (soldi / since-2019 / fabrication) 0; single @graph per page. Squash-merged #36 → main (4ee6816); bun run deploy:fhc (worker uploaded clean; expected exit-1 on the domain-attach, apex already bound). Live E2E: 4 IL pages + calculator 200 (were 404); Chicago aeo-il + phone + interlinks live; fabrication + soldi 0. Spec/lanes: docs/content/research/fhc-integration-2026-06/{SPEC,INVESTIGATION}.md. Next (needs Cam): verify fairhomecash.com in Resend → set LEAD_REPLY_FROM to activate seller auto-reply (#37); CF Email Routing for optout@/legal@/hello@ rights channels (#29); counsel confirm venue (#30); real Meta Pixel id (#27).


2026-06-26 — fairhomecash.com LIVE + organic-levers round (IndexNow, @graph, sitemap-index)

Deployed fairhomecash.com (worker fhc-pages, olelabs; domain bound via account API) and shipped the first no-ad-spend organic-levers round (ultracode workflow: 5 Exa research lanes → opus plan → senior-engineer implement → 4 adversarial reviewers → 0 must-fix). Live on the apex:

  • IndexNow — committed key 048b…fab served at the apex; scripts/indexnow-ping.ts (bun run indexnow --submit) POSTed 105 priority URLs → IndexNow 202 (Bing + Yandex), bypassing Bing's broken Webmaster UI entirely.
  • Entity @graph — FAQPage + HowTo folded INTO the @graph (verbatim-equal to visible copy), standalone blocks removed; segmented sitemap-index (states/cities/situations/static children); reciprocal hub↔spoke nearby-markets on every city page; gate-safe optional reviewer Person node (emitted only with a real FHC_REVIEWER_NAME — never fabricated).
  • Search Console — property auto-verified via the live GA4 tag; sitemap.xml submitted, 332 pages discovered. GA4 G-3553MET586 confirmed (stream = fairhomecash.com); Consent Mode v2 default-denied, so metrics.soldi.cc (first-party, unfiltered) is the measurement source of truth.

Verification: build 333 pages deterministic / audit exit 0 / firewall clean / legal pages byte-identical. Apex 200; key file 200; sitemap-index + 5 children 200; FAQPage in @graph. Merged to main via #22. Plan/research: docs/content/research/organic-levers-2026-06/PLAN.md. Next (needs Cam): GBP claim + sameAs profiles; real reviewer name for the byline; GA4 consent call; GSC indexation data before scaling page volume.


2026-06-26 — Monorepo consolidated → main; soldi surfaces deployed; analytics wired

Adopted the monorepo (#16) and stacked this session's work onto it, then one clean fast-forward to main (PR #14 — no conflicts, no legal content lost):

  • Consolidated the metrics dashboard, GA4 wiring, and platform-roadmap/research docs onto the monorepo+SEO head (integration/monorepo-consolidation): metrics → tools/metrics, GA4 re-ported onto the SEO'd sites/fhc-pages templates (off the legal pages), docs → docs/.
  • Merged to main via #14 (release/fhc-launch FF'd to integration; release→main FF). #17–#21 closed as consolidated-into-main; #16 auto-merged.
  • Deployed soldi surfaces (olelabs acct): app.soldi.cc (soldi 1c06d72e), docs.soldi.cc (soldi-docs 7a1a31c8), preview.soldi.cc (soldi-preview 66e70750); metrics.soldi.cc (soldi-metrics) live from the prior deploy.
  • GA4 G-3553MET586 wired (Consent Mode v2 default-denied + first-party beacon → metrics.soldi.cc); begins firing once fhc-pages deploys.

Verification: app bun run verify (112/112 tests); fhc-pages build 333 pages / audit 0 blockers / LAUNCH READY; all surfaces return 200. FHC apex DEPLOYED (Cam's go): fairhomecash.com live (worker fhc-pages, olelabs; domain bound via account API PUT /workers/domains, zone e70054044e07286f6136729ce2f3054a). 333 pages resolve; robots.txt Allow: / + AI crawlers (GPTBot/Perplexity/ClaudeBot); both sitemaps 200; GA4 G-3553MET586 firing; /collect beacon → metrics.soldi.cc (202); lead alerts (RESEND_API_KEY) → camolechowski@gmail.com. Privacy page keeps the as-if-registered draft placeholders (noindex) — fill once the LLC is formed. Next (Cam): Google Search Console verify + sitemap submit, Bing Webmaster, GA4 mark conversions, Google Business Profile.


2026-06-25 — FHC SEO/GEO optimization, round 1 (PR stacked on #16)

Researched the field (8 Exa lanes → docs/content/research/seo-2026-06/) + a staged opus plan (00-OPTIMIZATION-PLAN.md), then implemented the high-confidence on-site lanes on sites/fhc-pages/:

  • Entity graph (data/seo-schema.ts, NEW): consolidated the flat JSON-LD into one cross-linked @graph — Organization #org ← RealEstateAgent #business ← Service ← WebPage ← BreadcrumbList (Home>State>City) — with @id/sameAs (placeholders pending GBP/social) and build-derived dateModified/lastModifiedMonth (replaces the hardcoded 2026-06-07). Single brand-firewall string point.
  • City + state templates: a direct-answer-first "answer box" under the H1 (40–60 words, variant-rotated across 5 frames so the 263 pages are no longer byte-identical — the previously-dead variant system is now live); emit the @graph; state-page schema parity; hero LCP preload + fetchpriority + image dimensions; State breadcrumb tier; fixed the broken href="sell.html" link that shipped on 255 pages.
  • build.ts: explicit AI-crawler robots stanzas (GPTBot/OAI-SearchBot/PerplexityBot/ ClaudeBot/Google-Extended/Bingbot/Applebot…) + a new dist/llms.txt index.
  • audit.ts hardened: catches non-root-relative broken links, asserts @graph+@id, asserts no hardcoded dateModified. src/index.ts: edge Cache-Control (immutable assets, short HTML).
  • No fabricated reviews / AggregateRating (P0 legal gate respected). Brand firewall intact.

Verification: bun run build = 263 pages; bun run audit = exit 0, LAUNCH READY, 0 blockers; every dist/ soldi hit confirmed legit (the intentional "d/b/a Soldi" legal disclosure + the "Soldiers Field" landmark) — zero leaks in the new SEO surfaces.

Note for Cam: during the auto fix-loop an agent briefly stripped the "Fair Home Cash LLC d/b/a Soldi" disclosure from the static legal pages to satisfy an over-strict verify check — reverted; legal pages are untouched by this PR (the firewall's soldi check is a non-blocking warning, so the disclosure is fine).

Deferred to a follow-up (staged in the plan): the situation×geo new page type (/sell-{situation}-{city}), the content-generator change, and the off-site backlog (GBP/NAP + real sameAs URLs, backlinks, AI-citation monitoring).


2026-06-25 — lead-engine doc reskinned onto docs.soldi.cc (PR 16, fast-follow)

  • Built Zak's "Lead Engine — How It Was Built" writeup as a Soldi-dark page (docs/lead-engine.html), reskinned from the FHC navy/orange original into the closer-v2 system (Instrument Serif/Fraunces, --bull/--accent/--gold, grid texture). A confident, understated, blueprint-proof overview (per Cam): keeps the $0-lead proof + a plain description of how the system works, but (a) omits the implementation specifics (file names, page-variation mechanism, schema/stack/build details) so a client can't hand it to an LLM and rebuild it, and (b) drops the "this is hard / nobody can replicate it" framing — the dedicated moat section was cut for reading as defensive, and the difficulty-bragging was dialed back so the proof does the talking. (Two earlier cuts — dense-technical, then over-insistent — were revised to this.) Wired into docs/build.ts (copied to dist/lead-engine.html), served unlisted at docs.soldi.cc/lead-engine.
  • Entrance is CSS-only (visible-by-default rise keyframe, reduced-motion safe) — the initial IntersectionObserver version left below-fold content at opacity:0 for full-page captures / no-JS / SEO; replaced it and dropped the script (simpler + robust). Removed one dead CSS class.

Verification: bun run build:docs green (dist/lead-engine.html, 22.7 KB); deployed soldi-docs (version 27ed2b14+); live QA via chrome-devtools — full doc renders, zero console errors.

Next up: optional — link it under an "Internal" nav group; fold the source PDF's exact NJ figures if any change. fhc-pages deploy still held behind the P0 legal gate.


2026-06-25 — monorepo restructure: app/ · docs/ · previews/ · sites/fhc-pages/

  • Reorganized the repo into a Bun monorepo with four top-level deploy surfaces, each a workspace (or independent project), so every surface maps cleanly to its domain: app/ → app.soldi.cc · docs/ → docs.soldi.cc · previews/ → preview.soldi.cc · sites/fhc-pages/ → fairhomecash.com. All via history-preserving git mv (492 renames). Worker names + live domains unchanged → no redeploy needed, nothing breaks live.
  • The app moved wholesale into app/ (src/worker/migrations/public/index.html + all build config + .dev.vars). Only literal edit: wrangler.jsonc $schema../node_modules.
  • Docs collision resolved: tools/cloud-docs/*docs/; the repo-root markdown KB → docs/content/; client/questionnaire.htmldocs/questionnaire.html. docs/build.ts rewired (SURFACE/REPO_ROOT/DOCS=content).
  • previews/ (was tools/soldi-preview) and sites/fhc-pages/ (was tools/fhc-pages, kept independently installed to preserve its Soldi-free brand firewall) relocated; $schema depths + .claude/launch.json + the .claude/workflows/*.js paths repointed.
  • Root is now a bun-workspace orchestrator (workspaces: [app, docs, previews] + deploy:* scripts that run from root so the shared .env token resolves). New README.md; CLAUDE.md + AGENTS.md rewritten to the monorepo map; a per-workspace CLAUDE.md added to each surface.
  • Stashed Zak's "Lead Engine — How It Was Built" PDF + a content-upgrade brief at docs/content/lead-engine/ for the fast-follow.

Verification: bun run verify green (112 tests, build ok); bun run build:docs (6 internal

  • 2 client docs) and bun run build:fhc (263 pages) both build in their new homes; all four surfaces pass wrangler deploy --dry-run (app/docs/fhc with bindings, previews assets-only). No live deploy.

Next up: PR 16 — reskin + content-upgrade of the Lead Engine doc onto docs.soldi.cc (see docs/content/lead-engine/BRIEF.md). After merge + approval: redeploy each surface from root.


2026-06-04 — B+C drill-downs live; production floor fix (expired auctions) + self-heal; Sequences hidden

  • B+C drill-downs shipped + deployed (app.soldi.cc): reusable portal DetailDrawerPropertyDetail (Pipeline cards + Portfolio rows) + BuyerProfile (Leaderboard rows); Pipeline drag-to-move + drawer stage-edit via owner-scoped PUT /portfolios/:id/stage (action-logged, idempotent no-op) + movePipelineStage client. All three drawers render-checked; polished.
  • Same-day UI fixes (live): Comps ARV-band de-collision + comp cards; Pipeline dead-button cleanup (Filter removed, Add-lead toast); Portfolio range-toggle pill alignment; ChatPanel portal-to-body + inline position:fixed (drawer was trapped inline under a transformed ancestor); StageFunnel "Offer Out" crop. Deck: all 8 screenshots recaptured + funnel slide added.
  • Production "no properties" fix — root cause was NOT the bindings (D1 connected, all data intact). The 32 seeded auctions had expired (seeded days earlier; the every-minute cron settled them all → the Floor shows only active/discount → empty). Fix: (1) revived the auctions to live with fresh end-times; (2) self-healworker/scheduled.ts restockDemoFloor re-rolls ended-unsold auctions back to live each cron tick, so the demo floor never silently empties again.
  • Sequences hidden + disabled (owner decision — see docs/DECISIONS.md): removed from the nav + ⌘K command palette; /sequences redirects to the Floor. It's a read-only seeded view (send-engine unbuilt) → not demo-ready. Backend routes + seeded data left intact; fully reversible.

Verification: bun run verify green (112 tests, build ok); live checks — Floor renders 32 lots, ?demo=1 auto-login 302 valid, /auth/me + /pipeline authed return data (8 demo portfolios, 6 stages, 35 comps). Deployed: app → app.soldi.cc; deck → docs.soldi.cc/walkthrough.

Next up: Sequences cron send-engine (then un-hide); live Comps provider (Lofty/ATTOM+AI); B/C fast-follows (buyer-profile detail endpoint for by-distress/recent-wins/badges); demo ROI seed realism.


2026-06-02 — Wave 3 (realtime): Durable-Object live bids + chat, sub-market houses, CountdownTimer perf

Built the ENRICHMENT_PLAN "realtime wave" end-to-end — local-only; app deploy HELD (DO-migration hazard below). 5 phases, each verified + smoke-proven + committed:

  • P0 — Realtime backbone (c43f401): RealtimeRoom Durable Object (one class, two bindings AUCTION_ROOM + FLOOR_FEED) on the WebSocket Hibernation API; pure worker/realtime/events.ts (RealtimeEvent union + ring/presence/mappers, +7 tests); the WS upgrade is handled in a fast-path before Hono/cors (worker/index.ts) so the 101 passes unmodified; worker/routes/realtime.ts = routeRealtime + non-throwing broadcastToRoom. wrangler.jsonc gains the DO bindings + migration tag v1 (new_sqlite_classes:["RealtimeRoom"]). Smoke: WS hello/presence/pong on wrangler dev.
  • P2 — Live bids + real ticker (663b39b,6475990): bid.ts/buynow.ts/scheduled.ts broadcast bid/sold to the auction + floor rooms via c.executionCtx.waitUntil (can never fail a bid/settlement). src/lib/realtime.ts useRoom layers WS over the surviving 5s poll (graceful degradation → the un-deployed live app is unaffected). LeadDetail live-reload, LiveTicker real floor feed, PriceDisplay flash-on-increase. Smoke: a real bid POST propagated to both rooms.
  • P3 — Live chat (279a0e1,007e82d): per-auction ChatPanel (right-slide glass, live presence count, history seed + deduped append, ready-gated loading) on the auction room; LeadDetail "Room" toggle (socket only while open). Smoke: 2-tab echo + presence=2.
  • P4 — CountdownTimer perf (d9fde70): per-instance setInterval(1000) → one shared useNow() ticker (useSyncExternalStore); ~30 Floor countdowns share one timer.
  • P1 — Sub-market Auction Houses (561c815,4f65e2d): /market/:id page (metroLabel-encoded id) reusing AuctionGrid + scoped KpiBar; AuctionCard city-click enters a metro's house (Floor chip-filter preserved). Frontend-only.

Every UI phase ran the mandatory make-it-sexy → make-it-simpler pass (incl. LeadDetail split 449→296 via new LeadDetailDealSheet; a11y labels on chat/bid inputs).

Verification: bun run verify green after every phase — typecheck clean, 109 tests (102 + 7 realtime), build ok (~635kB / 191kB gz). Local WS smokes (P0/P2/P3) on wrangler dev; chrome-devtools render-checks on each polished page.

⚠️ DEPLOY HAZARD — DO migration pending: wrangler.jsonc now declares RealtimeRoom + migration tag v1, so the next wrangler deploy of the soldi worker applies that DO migration to app.soldi.cc (intentional — that deploy is what makes realtime live). Until then the live app is unchanged (WS connects fail → clients fall back to the poll / mock ticker). db:reset:local clears only D1, not DO storage — rm -rf .wrangler/state/v3/do before a clean local reseed.

Next up: owner-approved app deploy to make realtime live + recapture the deck shots for the realtime surfaces; optional server ?market= param + tags[]; manualChunks for the >500 kB bundle.


2026-06-02 — Sexy-everywhere: Motion + ⌘K + Sonner + OKLCH/glass + per-page enrichment

Worked the make-it-sexy group skills into EVERY page (then make-it-simpler). 20-agent workflow: Foundation → 9 pages (sexy+enrich) → simpler → verify.

  • Deps added: motion (motion/react), sonner, cmdk. App wrapped in <MotionConfig reducedMotion="user"> + a global Sonner <Toaster>.
  • ⌘K command palette (src/components/CommandPalette.tsx, cmdk + Motion + glass): navigate to any page + quick actions; ⌘K hint chip in TopNav.
  • index.css (additive): OKLCH elevation ramp --elev-0..3 + .glass (specular, fallbacks) + CLS guards (scrollbar-gutter: stable, media aspect-ratio).
  • Per-page enrichment + Motion: Floor cards now data-rich ($/sqft, equity bar, mortgage, year, quality-breakdown spark, distress detail, distress-tinted spine, quality-tier ring) + sort (6-way) + distress + equity-tier filters; Lead detail gained media placeholder, Seller Motivation card, $/sqft+equity tiles, quality bars, bid-history sparkline, optimistic bidding; Portfolio Capital Flow viz + count-ups + 167×/+2400% ROI; Pipeline/Comps/Sequences/Leaderboard/Activity/Login all got Motion entrance/stagger/hover + count-ups + richer viz. Marketplace split into Marketplace.tsx + MarketplaceParts.tsx + FloorControls.tsx + AuctionCardMeta.tsx (all < 400 lines). format.ts gained pricePerSqft/sortAuctions/equityTier/qualitySpark/etc.

Fixes during QA

  • vite.config.ts: added resolve.dedupe: ['react','react-dom'] — Motion pulled a 2nd React copy into the Vite dev optimizer → "Invalid hook call" crashes. (Rollup prod build was unaffected, but this fixes vite dev.)
  • AuctionCard spine: moved from ::after to ::before — it collided with the global .sheen hover-shine (::after, skewed), which skewed the distress spine into a diagonal streak across every card. Now a clean left-edge bar; sheen works on hover.

Verification: bun run verify → typecheck clean · 102 tests · build green (JS 615kB / gzip 186kB incl. motion/cmdk/sonner). Browser-QA'd all pages (Floor cards, Lead, Comps, Portfolio, ⌘K palette) — no console errors (only browser-extension noise), no artifacts after the spine fix. Deployed: app → app.soldi.cc (new bundle); deck → docs.soldi.cc/walkthrough with all 8 screenshots recaptured (the "after" set).

Known minor: Comps ARV-band comp-dot labels bunch when sale prices cluster (cosmetic); JS chunk > 500kB (Vite warning) — could add manualChunks/LazyMotion later.

Next up: Comps ARV-label de-collision + a manualChunks split; then realtime (Durable-Object live bidding/chat) + Sequences send-engine per ENRICHMENT_PLAN.md.


2026-06-01 — Finalization: Comps + Sequences built, all pages wired, zero disabled tabs

Client-ready pass. Every nav tab is now a real, working, live-data page — no disabled flags, no mock/placeholder data.

  • Comps (/comps, new) — 0006_comps.sql (comp_queries/comparables/arv_estimates), worker/comps.ts deterministic provider + ARV/70%-rule math (+15 tests), routes/comps.ts (POST /comps/run, GET /user/comps/history), src/pages/Comps.tsx (ARV band + confidence + 70% offer marker + AI deal-read + 5 comp cards). PropStream replacement; mock provider swaps to Lofty/ATTOM+AI behind the same contract.
  • Sequences (/sequences, new) — 0007_sequences.sql (4 tables + rich seed: 3 sequences/steps/enrollments/messages), routes/sequences.ts, src/pages/Sequences.tsx (cadence list + step timeline + engagement stats). Follow Up Boss replacement (read view).
  • Portfolio wired → routes/portfolio.ts real KPIs (spend/assigned/net ROI/win rate)
    • Recent Wins, 30D/90D/YTD/All. Leaderboard wired → routes/leaderboard.ts + 0008_leaderboard_seed.sql (9 ranked buyers, podium, streaks). Activity wired → routes/activity.ts real bid/win/listing events (5s poll).
  • Integration: TopNav renamed to Floor, soonLinks/disabled tabs DELETED, Comps + Sequences added as real NavLinks; routes in App.tsx; 5 routes mounted in worker/index.ts. Final nav: Floor · Pipeline · Comps · Sequences · Activity · Portfolio · Leaderboard.
  • QA fixes (browser pass, all 8 pages): Activity actor-less rows now read "New listing — …" (was a bare "listed" with a missing-name gap); Floor "MARKETS" label no longer clipped to "KETS" (moved outside the scroll/edge-fade); 0009_demo_polish.sql pulls the assigned deal into the window + stamps its $22K fee so Portfolio shows +2400% ROI / 17% win and Pipeline Assigned MTD 1 · $22,000 (were $0 / −100%).
  • Deployed: remote D1 migrated 0005–0009; app redeployed (app.soldi.cc / workers.dev) — all 5 new endpoints 200. Deck refreshed: Comps/Sequences slides flipped from "coming soon" → live, all 8 "after" screenshots recaptured to tools/cloud-docs/shots/, redeployed (docs.soldi.cc/walkthrough).

Verification: bun run verify → typecheck clean · 102 tests · build green; migrations 0001–0009 apply; browser QA of all 8 pages; zero soon/disabled in TopNav.

Next up: Sequences cron send-engine (Resend); Comps live provider (Lofty/ATTOM+AI); realtime (Durable-Object live chat + Kalshi-style bid animations) per ENRICHMENT_PLAN.md.


2026-06-01 — Floor: Auction Floor rename + geo sub-markets + KPI bar + wider seed

Turned the flat slice-01 feed into a navigable trading floor. Renamed the public page to Auction Floor (page <h1>; nav label Floor; route stays /, file stays src/pages/Marketplace.tsx). Added a client-derived geo sub-market layer over the existing feed — no API change: GET /api/v1/auctions already returns the full embedded lead with city/state, so metros are a pure projection.

  • Geo filtering — canonical metroLabel(lead)"City, ST" (src/lib/format.ts) drives all three entry points: the Markets chip strip (shown when >1 metro, counts track the active status tab — filters compose), a clickable city on each card (.ac-geo, onSelectMetro; preventDefault so it doesn't open the lead), and a ?market= deep-link (URL is the source of truth via useSearchParams; replace-writes, deletes param on All, self-heals to All when the active metro leaves the cohort). Grid cohortKey = `${tab}|${market}` so any filter change re-runs the entrance cascade.
  • KPI bar (KpiBar) — four tiles over the full active cohort: Total Volume, Avg Price, Hot (quality ≥ 80), Markets (distinct metro count). INTEGER cents via formatPrice; tnum figures.
  • Wider seed (migrations/0005_floor_seed.sql) — +20 leads / +20 auctions (8 new metros: LA, Brooklyn, Tampa, Charlotte, Las Vegas, Denver, Cleveland, San Antonio + extras in Chicago/Phoenix/Atlanta). Additive INSERT OR IGNORE, D1 separate-modifier datetimes, 2 discount lots.
  • PRD: docs/prd/AUCTION_FLOOR.md.

Verification evidence

$ bun run test                                  → 87 passed (7 files)
   pricing 8 · bidding 20 · mappers 8 · settlement 7
   format 16 · pipeline 14 · auth 14
$ bun run build  (tsc -b && vite build)         → clean
   67 modules · index.js 296.94 kB (gzip 91.87) · index.css 58.02 kB (gzip 11.13)

$ rm -rf .wrangler/state/v3/d1 && bun run db:migrate:local
   0001…0005 all ✅  (0005_floor_seed applies clean)

$ wrangler d1 execute soldi --local --command "SELECT … FROM auctions/leads"
   → feed_count (status IN active,discount) : 32
     total_auctions                         : 32
     distinct_markets                       : 15
     total_leads                            : 33

Floor count is now 32 active auctions across 15 metros (was 12 in slice 01). All touched files <400 lines; no comments on untouched code; no new secrets; not deployed.

Next up

Re-capture .qa-walkthrough/ Floor screenshots (geo strip + KPI bar are the new "after"), refresh the walkthrough deck's Floor frame, then start the per-metro "auction house" drill-down (/market/:metro) or live bid animations per docs/ENRICHMENT_PLAN.md.


2026-06-01 — Ops: deck iframe-default, demo auto-login, AGENTS/CLAUDE, enrichment review

  • app.soldi.cc custom domain added (by owner via dashboard) → app live there + workers.dev.
  • Deck now defaults to the live iframe for public pages (Floor, Lead); authed pages (Pipeline, Portfolio) default to the populated screenshot + "Open live ↗" (new tab). Deck embeds the workers.dev origin (reliable in cross-origin iframes; the just-added app.soldi.cc was blank in-iframe — custom-domain edge still settling).
  • ?demo=1 auto-login added to the worker (logs in the seeded demo account, redirects clean) for first-party "Open live" links. Session cookie switched to SameSite=None; Secure for iframe embedding (demo posture — revisit CSRF for prod). 87 tests green (updated cookie test). Note: ?demo=1 only fires on non-asset routes (Static Assets serve / before the worker), which is fine — authed deep-links (/pipeline etc.) are non-asset.
  • AGENTS.md + CLAUDE.md added: bracket every workstream with a start (read ledger, bootstrap+verify) and end (verify → refresh deck+screenshots+docs → redeploy → flag stale) discipline; sexy+simplify mandatory; infra/demo quick-ref.
  • Enrichment review (soldi-enrichment-review workflow, 25 agents: 9 page reviews → 59 subcomponent deep-dives) → synthesized to docs/ENRICHMENT_PLAN.md: per-page beef-ups/metrics/layout-fixes/standalone-verdict/seed plan; cross-cutting (geo sub-markets /"auction houses", Durable-Object live chat, Kalshi-style live bid animations); notable fixes (CountdownTimer per-instance setInterval perf bug; QualityBadge/HotBadge DRY). Comps + Sequences confirmed present in v2 prototype + specs (not lost) — queued to build.
  • Before/after baseline: .qa-walkthrough/ screenshots = "before"; re-capture after enrichment.

2026-06-01 — Ops: live app deploy + interactive walkthrough deck

Live app deployed (first remote deploy, explicit owner approval): created remote D1 soldi (d7b25c82…), wired into wrangler.jsonc, applied migrations 0001–0004

  • seed to --remote, set remote SESSION_SECRET, deployed → https://soldi.camolechowski.workers.dev (workers_dev:true; cron settlement live). Verified: health OK, 12 auctions from remote D1, SPA 200, login demo@soldi.cc/soldidemo. The app.soldi.cc custom domain failed (API token lacks Workers-Routes perm on the soldi.cc zone — error 10000); add via dashboard or a zone-scoped token later.

Interactive walkthrough deckhttps://docs.soldi.cc/walkthrough (path on the existing soldi-docs static-assets worker). tools/cloud-docs/walkthrough.html: a self-contained 13-slide presenter deck — intro + one slide per page (Floor, Bidding, Pipeline, Portfolio, Leaderboard, Activity, Comps, Sequences, Accounts, Admin) + consolidated decisions + roadmap. Per slide: status badge (live/seeded/soon/planned), "what it does", a "Decisions we need from you" callout, and a media pane that shows the captured screenshot with a ▶ Go live toggle that swaps in a live <iframe> of the deployed app (+ "Open in new tab"). Toolbar/keys: L live, D spotlight decisions, N presenter notes, A annotate (drop/drag/type sticky notes, saved to localStorage — the "superimpose content" layer); ←/→ + number-key nav + slide rail. Screenshots from the QA walkthrough agent (shots/) baked into the build. Verified live: /walkthrough 200, shots 200, Go-live iframe loads the real marketplace.

Caveat: authed pages (Pipeline/Portfolio) inside the cross-origin iframe render logged-out (SameSite=Lax session cookie isn't sent third-party) — use each slide's "Open in new tab ↗" for authed interaction (demo login). Floor/Lead are fully interactive in-iframe (public).


2026-06-01 — Slice 05: Pipeline board (read-only CRM kanban)

What shipped

  • migrations/0003_pipeline.sql — reconciles portfolios.status to the 6-stage enum (new | contacted | offer | under-contract | assigned | dead; legacy follow_up/under_contract/converted mapped over), adds portfolio_stages (1:1, current_stage/stage_entered_at/next_action_*/offer_sent_amount_cents/ assignment_*/stale_days_threshold) + portfolio_actions (activity log) + portfolios.next_action_due_at (indexed). Seeds ~6 demo portfolios for U_SEED_GHOST spread across stages (incl. a stale "offer" 18d row, an under-contract, an assigned) with matching stage + action rows.
  • worker/pipeline.ts — pure aggregation (no D1): groupCardsByStage (all 6 stages always present, fixed order), computeKpis (leadsInPipe excl. dead, underContract count+gpCents, assignedMtd, conversionPct guarded against /0, avgStageAgeDays, staleCount), applyFilter, isStale (per-row threshold), rowToCard, buildPipeline. worker/pipeline.test.ts (+14 tests).
  • worker/routes/pipeline.tsGET /pipeline?filter=…: currentUser gate (401), Zod filter enum (400 on bad value), joins portfolios ⨝ portfolio_stages ⨝ leads for the session user, stage_age_days computed via julianday('now') - julianday(stage_entered_at) in SQL (never client-parsed). Mounted in worker/index.ts via api.route('/', pipelineRoutes).
  • Frontend: fetchPipeline() + Pipeline DTO types in src/lib/api.ts; relativeDue() (today/overdue/future/none) in src/lib/format.ts (+4 tests); src/pages/Pipeline.tsx 6-column kanban (6→3 @1300px scoped <style>, stage-colored left borders, KPI row, filter chips w/ counts, card next-action/offer/progress, .skeleton + empty + error states); /pipeline route in App.tsx; Pipeline promoted from soonLinks to a real NavLink in TopNav (Comps/Sequences still disabled).

Verification

$ bun run verify  → typecheck clean · Tests 87 passed (87) · build green
  (69 prior + 14 worker/pipeline.test.ts + 4 new relativeDue cases)
  worker/pipeline.test.ts: grouping (6 stages, empty stages count:0),
    KPIs (dead excluded, gpCents, assignedMtd, conversionPct no NaN on empty),
    applyFilter (due_today/overdue/stale_14d/under_contract; all = identity),
    per-row stale threshold.

As-built divergence from PRD: third stage key shipped as offer (display "Offer Out"), not the PRD's offer-sent, consistently across the enum, migration, and API DTO. under_contract filter key unchanged. docs/prd/FEATURE.md updated to SHIPPED + reconciled.

Demo access: migrations/0004_demo_login.sql sets the seeded board owner (U_SEED_GHOST) to demo@soldi.cc / soldidemo (PBKDF2 hash computed via worker/auth.ts) so the populated Pipeline is reachable in the demo — /pipeline is gated to the logged-in user, so a fresh signup sees an empty board. Independently re-verified: 87 tests, typecheck/build green, 0001–0004 apply clean, GET /pipeline returns all 6 stages + KPIs, kanban screenshot confirmed.

Process note: this slice was the first run of the reusable .claude/workflows/feature-lifecycle.js (discover→plan→build/verify→sexy→ simplify→confirm→document). args did not reach the script, so the Discover phase read docs/ROADMAP.md and self-selected Pipeline — a useful robustness property, but pass-args propagation should be confirmed for targeted runs.

Next up: Pipeline writes (slice 3) — PUT /portfolios/:id/stage (drag-drop moves) + POST …/actions + next-action edits, with the sequence-enrollment event hook the portfolio_actions table was scaffolded for.


2026-06-01 — Slice 04: Keystone — cron auction resolution + buy-it-now

What shipped

  • worker/settlement.ts — pure settleOutcome({status,endTimeIso,nowMs,topBid})skip | sold | unsold (uses parseDbTime). settlement.test.ts (+7 tests).
  • worker/scheduled.tssettleDueAuctions(env,now) + exported scheduled() handler; cron ["* * * * *"] in wrangler.jsonc. Settles auctions past end_time: SOLD → status ended_sold + winning ids, converts leader hold→charge (held_balance/balance down, total_spent/leads_won up, streak bump), wallet_transactions 'charge', inserts portfolios row; UNSOLD → ended_unsold. Status-guarded UPDATEs (idempotent) + per-auction try/catch (resilient).
  • worker/routes/buynow.tsPOST /auctions/:id/buy-now: instant settlement (insert is_buy_now bid, release prior leader hold, charge buyer, ended_sold, portfolio row). Errors 401/404/409/402.
  • Frontend: buyNow() in api.ts; LeadDetail "Buy it now" button enabled with submitBuyNow (mirrors submitBid; toast + balance refresh). Skeleton extracted to keep the file < 400 lines.

Verification

$ bun run verify  → typecheck clean · Tests 69 passed (69) · build green
# wrangler dev --test-scheduled on :8787 (fresh bootstrap)
buy-now A_CHI_TAXLIEN_03 → bought:true, status ended_sold; buyer 50000→39200,
   totalSpent 10800, leadsWon 1, streak 1; portfolios row (status 'new') created.
real bid 13835 (held 13835) → force end_time past → /__scheduled trigger →
   auction ended_sold (winning_user_id set); buyer 39200→25365, held→0,
   totalSpent 24635, leadsWon 2, streak 2; portfolios=2. Idempotent on re-run.

Next up: Portfolio KPIs + weekly Leaderboard from D1 (now that settlement populates real data); then CI + a Playwright bid/buy-now e2e.


2026-06-01 — Ops: cloud-docs response persistence (KV)

Added KV-backed submission capture to the soldi-docs worker:

  • KV namespace RESPONSES (29c8518…) bound in tools/cloud-docs/wrangler.jsonc.
  • Worker: POST /api/responses stores {id, submittedAt, country, userAgent, answers} under resp:<id>; GET /api/responses[/:id] lists/fetches. All open (light, non-confidential — no auth, no token to paste). Everything else → assets.
  • Questionnaire: added a "Submit to soldi →" button that POSTs the export object to /api/responses (graceful fallback to local download when offline).
  • Verified live: POST→{ok,id}, list/by-id round-trip (country US, answers intact), invalid JSON→400, open GET→200. Read responses: curl https://soldi-docs.camolechowski.workers.dev/api/responses.

Docs IA + custom domain: home is now a client-doc index ("Released to you" = Product Direction; "Internal references" = roadmap/specs/build-log). The questionnaire is served at the clean path /product-direction (old /questionnaire.html 307→redirects). Custom domain docs.soldi.cc added to the worker (routes custom_domain; soldi.cc is an active zone on the account) — workers.dev URL still serves too.


2026-06-01 — Ops: reproducible setup + codebase-wide simplify (round 2)

Setup hardened: pinned wrangler dev to :8787; added bootstrap (reset+migrate+seed), start (build+dev), verify (typecheck+test+build), db:reset:local. Clean-slate bootstrap → verify → start proven: health OK, 12 auctions from D1, SPA 200.

Simplify round 2 (8 agents, disjoint lanes incl. worker):

  • worker/index.ts 402→36 lines, split into worker/routes/{auctions,bid,auth}.ts
    • shared worker/users.ts (UserRow/publicUser/USER_SELECT_SQL/currentUser); currentUser(c) takes the Context directly; STATUS_WHERE map; deduped bids SQL; removed dead SessionVars.
  • frontend: deduped FeedState, QUALITY_ROWS map, hoisted per-render consts, StatusDot primitive, postJson helper in api.ts, run() helper in session.tsx, deleted dead formatPriceDelta.
  • index.css: removed 23 dead back-compat aliases (verified zero orphaned utility usages across src/).
  • Verified: typecheck clean · 62/62 tests · build green · 0 orphaned classes · login + marketplace screenshots confirm no visual regression. Snapshot: .backup_src_round2.tgz.

2026-06-01 — Ops: UI polish pass + cloud docs deployed

Polish workflow (25 agents): per-page apply of the make-it-sexy sub-skills (cutting-edge-ux-patterns, fluid-micro-interactions, high-end-ui-assembly, modern-visual-aesthetics; rsc-streaming-architectures correctly skipped for a Vite SPA) then make-it-simpler, then a final unscoped DRY pass. Net: micro- interactions/reveal staggers, deduped FeedState/SectionHeading/Collapse, DRYed bid-reload + min-bid rounding, null-safe badges. No new deps; index.css frozen except the solo final pass. Verified: typecheck clean · 62/62 tests · build green · screenshot. Pre-pass snapshot at .backup_src_phaseUX.tgz.

Cloud docs deployedtools/cloud-docs/ (Workers Static Assets). build.ts renders docs/*.md + BUILD_LOG.md → soldi-branded HTML and folds in the client questionnaire. Live (personal CF account, creds from .env): https://soldi-docs.camolechowski.workers.dev (routes: /roadmap, /design-system, /spec-comps, /spec-pipeline, /spec-sequences, /build-log, /questionnaire.html).

Gotcha: an assets-only Worker (no main) returned a persistent edge error 1105 / 503 on workers.dev despite a successful upload and an enabled subdomain. Fix: add a minimal main entry (src/index.tsenv.ASSETS.fetch(req)) with an ASSETS binding — the canonical Workers-Static-Assets form. Use this in the tools/ wrangler template.


2026-06-01 — Phase A: Design-system migration (closer-v2 reskin, still "soldi")

What shipped (foundation written inline; 4 page-restyles fanned out in parallel)

  • src/index.css — rewrote @theme + :root to the closer-v2 metallic palette (bull/bear/warn/hot/accent-lavender/gold + surface/text/border tiers), added Fraunces/Instrument Serif/Hanken Grotesk/JetBrains Mono tokens, the 56px grid wash (body::before), new shadows/radii, keyframes (price-flash, urgent-pulse, reveal-up), and a button variant system (.btn-primary now bull, .btn, .btn-ghost, .btn-danger, .pill, .chip, .qscore). Old token names kept as aliases so utilities keep resolving during the migration. No Robinhood green.
  • index.html — swapped font <link> to Fraunces/Instrument Serif/Hanken Grotesk/ JetBrains Mono; body bg #0B0D0E.
  • Restyle agents (disjoint files): shell (TopNav wordmark = "soldi" in Instrument Serif + bull dot; tab-bar nav with disabled Comps/Pipeline/Sequences "soon" tabs; LiveTicker; Layout), floor+cards+ui (Marketplace "The floor", AuctionCard/Grid, QualityBadge→.qscore conic circle, PriceDisplay/Countdown/ HotBadge/DistressTag), lead-detail (bidding panel — logic preserved), and portfolio+misc (Portfolio/Leaderboard/Activity/Login).
  • Name stays "soldi" everywhere (worker, package, wordmark). Only "closer" reference left is an internal doc comment noting the prototype's origin.

Verification (commands + key output)

$ bun run typecheck   → tsc -b clean
$ bun run test        → Test Files 5 passed (5) · Tests 62 passed (62)   (logic intact)
$ bun run build       → ✓ built; dist/assets/index-*.css 35.00 kB
# wrangler dev :8787 + chrome-devtools screenshots:
#   / (marketplace)        → soldi wordmark, tab bar, "The floor" (Fraunces),
#                            conic quality circles, distress/equity/age chips,
#                            mono prices, bull quick-bid buttons.
#   /lead/A_PHX_PROBATE_07 → Instrument Serif address, Fraunces section heads,
#                            bid input prefilled to min ($250), bull "Sign in to
#                            bid" CTA, restyled bid history. Bidding UI intact.

Next up

Phase B — fan out the 3 new pages (Pipeline read · Comps UI+mock · Sequences read) per docs/ROADMAP.md, each with its own migration + Hono route + page, worktree-isolated, verified per vertical.


2026-06-01 — Slice 03: Bidding end-to-end (increments, holds, anti-snipe)

What shipped

  • worker/bidding.ts — pure, unit-testable rules: minBidIncrement ($5 or 5%, whichever greater), minNextBid, applyAntiSnipe (final-2-min window → +2min, max 5 extensions), validateBid, and parseDbTime (normalizes SQLite's space-separated datetime() output to ISO-UTC).
  • worker/index.tsPOST /api/v1/auctions/:id/bid: auth-gated, Zod body, loads auction + current leader, validates, applies anti-snipe, and writes atomically via DB.batch — insert bid, bump current_price/bid_count/ end_time/snipe_extensions, place the new leader's hold, release the prior leader's hold, and record hold/release wallet_transactions. Returns the refreshed auction + extended flag. Error map: 401 unauthorized, 404 not_found, 409 auction_ended/already_leading, 422 bid_too_low, 402 insufficient_funds.
  • worker/bidding.test.ts — 20 unit tests (increment floor/percent, snipe window/boundary/cap/ended, db-time parsing both formats, all validation paths).
  • src/lib/api.tsplaceBid() helper.
  • src/pages/LeadDetail.tsx — live bid form (input prefilled to min next bid), error-code→toast mapping, "Extended! 2:00 added" toast on anti-snipe, 5s auction polling (PRD §12), balance refresh after a successful bid.

Verification (commands + key output)

$ bun run typecheck   → tsc -b clean (exit 0)
$ bun run test        → Test Files 5 passed (5) · Tests 62 passed (62)
$ bun run build       → ✓ 62 modules transformed; built in ~0.6s

# local D1 + wrangler dev on :8787 (after rm -rf .wrangler/state/v3/d1
#   && bun run db:migrate:local && bun run db:exec:local migrations/0002_seed.sql)
POST /auctions/A_CHI_PREFCL_01/bid  (no auth)       → 401
POST … {amount:13000}  (< minNext 13335)           → 422 bid_too_low
POST … {amount:60000}  (> available 50000)          → 402 insufficient_funds
POST … {amount:13335}  (valid, bidder A)            → 201 currentPrice 13335, bidCount 6
POST … {amount:15000}  (A already leader)           → 409 already_leading
GET  /auth/me (A)                                    → heldBalance 13335, balance 50000
POST … {amount:15000}  (bidder B outbids A)          → 201
GET  /auth/me (A)  → heldBalance 0   |  (B) → heldBalance 15000   (prior hold released)
wallet_transactions(A) → hold 13335 then release 13335 (reference A_CHI_PREFCL_01)
# anti-snipe: forced A_DAL_CODE_09 end_time to +60s, bid as B
POST … {amount:7850}  → {extended:true}; end_time 04:14:51 → 04:16:51 (+2:00); snipe_extensions 0→1

Gotcha caught during verify

D1's datetime() returns space-separated timestamps (2026-06-01 04:13:27, no T, no Z), which Date.parse turns to NaN in workerd. First anti-snipe test silently failed (extended:false, no extension) AND the auction_ended guard would never trip (NaN <= now is false). Added parseDbTime to normalize both SQLite and ISO formats; re-verified the extension fires (+2min, ext 0→1).

Next up

Design-system migration (foundation slice) per docs/DESIGN_SYSTEM.md — port the closer v2 tokens/typography/components into index.css + index.html and restyle the existing pages, no data changes. Then the 3 new pages (Pipeline, Comps, Sequences) per docs/ROADMAP.md Phase B.


2026-05-29 — Slice 01: Marketplace feed end-to-end from D1

What shipped

  • migrations/0002_seed.sql — 13 leads + 12 auctions across IL/FL/AZ/TX/GA/CA, all distress types, quality 34–91, freshness from 15min to 32h old, 1 discount auction, 1 placeholder user, 5-bid history on the Phoenix probate auction. All times anchored to datetime('now', ...) so "ending soon"/"new" tabs stay realistic across runs.
  • worker/mappers.ts — snake_case D1 row → camelCase frontend Auction DTO with nested lead and bids[], including QualityBreakdown JSON parsing guarded by Zod and a fallback for malformed JSON. Shared AUCTION_SELECT_SQL for list + detail.
  • worker/index.tsGET /api/v1/auctions?status=active|discount|all&limit=N (Zod-validated query) and GET /api/v1/auctions/:id returning the auction with full bid history joined to users.display_handle. Proper 404 for unknown ids.
  • worker/mappers.test.ts — 8 unit tests covering the row→DTO mapping, JSON parse fallbacks, discount flags, status coercion, bid attachment.
  • src/lib/api.ts — tiny typed fetch helpers (fetchAuctions, fetchAuction) with AbortSignal support.
  • src/pages/Marketplace.tsx — replaces MOCK_AUCTIONS with live API. Loading skeleton, error card, empty-tab card. Tab filters now run against real D1 data.
  • src/pages/LeadDetail.tsx — fetches the single auction by id, renders a bid history panel when present, loading/error/missing states.

Verification (commands + key output)

$ bun run typecheck
$ tsc -b
# (clean)

$ bun run build
$ tsc -b && vite build
✓ 60 modules transformed.
dist/index.html                   0.82 kB │ gzip:  0.46 kB
dist/assets/index-Cf1hfNuH.css   23.05 kB │ gzip:  5.25 kB
dist/assets/index-CLIXHb-m.js   252.42 kB │ gzip: 79.57 kB
✓ built in 574ms

$ bun run test
 Test Files  3 passed (3)
      Tests  28 passed (28)

Local D1 + wrangler dev smoke (after rm -rf .wrangler/state/v3/d1 && bun run db:migrate:local):

$ curl -sS http://localhost:8788/api/v1/health
{"ok":true,"service":"soldi","time":"2026-05-30T04:13:07.901Z"}

$ curl 'http://localhost:8788/api/v1/auctions?status=all&limit=100'  → count: 12
  A_CHI_TAXLIEN_03   Chicago, IL    q=62 price=$54   ends 04:54 (ending-soon)
  A_PHX_TAXLIEN_13   Phoenix, AZ    q=80 price=$29   status=discount
  A_CHI_PREFCL_01    Chicago, IL    q=87 price=$127
  A_PHX_PROBATE_07   Phoenix, AZ    q=89 price=$238
  A_MIA_DIVORCE_06   Miami, FL      q=81 price=$172
  A_DAL_ABSENTEE_08  Dallas, TX     q=65 price=$62
  A_ATL_PREFCL_10    Atlanta, GA    q=76 price=$111
  A_CHI_PROBATE_02   Chicago, IL    q=78 price=$142
  A_MIA_TAXLIEN_05   Miami, FL      q=91 price=$210
  A_HOU_PROBATE_11   Houston, TX    q=83 price=$132
  A_SPRING_VACANT_04 Springfield,IL q=34 price=$25
  A_DAL_CODE_09      Dallas, TX     q=70 price=$69

$ curl http://localhost:8788/api/v1/auctions/A_PHX_PROBATE_07
  bids: 5 (PhoenixVolume @ $190 → $205 → $218 → $225 → $238)
  qualityBreakdown: {equity:25, motivation:25, propertyValue:20, contactQuality:12, dataCompleteness:7}

$ curl /api/v1/auctions/does_not_exist  → HTTP 404 {"error":"not_found"}
$ curl '/api/v1/auctions?status=discount' → count: 1 (A_PHX_TAXLIEN_13)

$ curl / → HTTP 200, <title>soldi - Distressed Property Lead Auctions</title>
$ curl /lead/A_CHI_PREFCL_01 → HTTP 200 (SPA fallback)

Gotcha caught during verify

First seed run inserted only 9/12 auctions silently. Root cause: SQLite datetime() takes modifiers as separate arguments — '+23 hours 30 minutes' is not a valid single modifier and returns NULL, which then violated end_time NOT NULL under INSERT OR IGNORE. Fixed three rows to use datetime('now','+23 hours','+30 minutes') form. Re-applied migrations after wiping .wrangler/state/v3/d1; now 12/12.

Next up

Auth + identity (the second slice that unlocks bidding, watching, portfolio, wallet). Concretely: a register/login pair on /api/v1/auth, password hashing with the Web Crypto API (PBKDF2 — no node bcrypt in Workers), a signed session cookie or short JWT, a useSession() hook, and a GET /user/profile endpoint backed by the existing users row. The bidding slice depends on having a user_id to charge/hold against.


2026-05-30 — Slice 02: Auth + identity end-to-end

What shipped

  • worker/auth.ts — Web Crypto PBKDF2-SHA256 password hashing (100k iterations, 16-byte salt, 32-byte hash; stored as pbkdf2$<iters>$<salt-b64>$<hash-b64>), constant-time compare, HMAC-SHA256-signed session token (<body-b64>.<sig-b64>, 30-day TTL, expiry embedded in payload), buildSessionCookie / clearSessionCookie / readSessionCookie helpers (HttpOnly, SameSite=Lax), and generateId / generateHandleFromName helpers.
  • worker/types.tsEnv now carries SESSION_SECRET. Local secret in .dev.vars (gitignored), required by both /auth/register and /auth/login.
  • worker/index.ts — five new endpoints under /api/v1:
    • POST /auth/register (Zod-validated {email, password>=8, name}, 409 on dup email, sets cookie, also writes a wallet_transactions signup_bonus row crediting the $500 demo balance).
    • POST /auth/login (verifies hash, updates last_active_at, sets cookie, 401 on bad creds).
    • POST /auth/logout (clears cookie).
    • GET /auth/me (returns { user | null }, never 401 — used by the session hook on every page load).
    • GET /user/profile (401 if unauth; returns the same public-user shape).
    • Shared USER_SELECT_SQL + publicUser() redact password_hash and other internal flags before returning to the client.
  • worker/auth.test.ts — 14 unit tests: salting, wrong-password, malformed-hash, token round-trip, tampered body, foreign secret, expired token, malformed token, cookie shape, cookie clear, cookie read, id uniqueness, handle suffix.
  • src/lib/api.tsfetchMe / login / register / logout typed helpers with credentials: 'same-origin' and a shared readError that pulls the API's { error } code out of the body.
  • src/lib/session.tsxSessionProvider + useSession() hook with { user, loading, error } state plus login/register/logout/refresh actions; auto-fetches /auth/me on mount.
  • src/pages/Login.tsx — dark Robinhood-style login + register form (toggleable, ?mode=register deep-link), inline error mapping for the API error codes (invalid_credentials, email_taken, invalid_body, server_misconfigured), accent-glow focus rings.
  • src/layouts/TopNav.tsx — replaces the mock balance + initials chip with the real session. Shows a loading shimmer while /auth/me resolves, a real balance pill + initials button (with a popover for Sign out) once authed, and Sign in / Sign up links when not authed.
  • src/App.tsx — wraps the router in <SessionProvider> and adds the /login route.

Verification (commands + key output)

$ bun run typecheck
$ tsc -b
# (clean — exit 0, no output)

$ bun run test
 Test Files  4 passed (4)
      Tests  42 passed (42)

$ bun run build
 ✓ 62 modules transformed.
 dist/index.html                   0.82 kB │ gzip:  0.46 kB
 dist/assets/index-DGVY73fC.css   27.88 kB │ gzip:  5.92 kB
 dist/assets/index-DD7iVCN9.js   260.12 kB │ gzip: 81.49 kB
 ✓ built in 593ms

Local wrangler dev smoke (after wiping .wrangler/state/v3/d1 and re-running bun run db:migrate:local). The dev server bound to a random port (59545) this run — wrangler@3.114.17 no longer pins to 8788; check the boot banner.

$ curl /api/v1/auth/me              → {"user":null}
$ curl /api/v1/user/profile         → HTTP/1.1 401 Unauthorized
$ curl POST /auth/register {bad}    → HTTP/1.1 400 Bad Request
                                       (Zod issues for email/password/name)
$ curl POST /auth/register          → HTTP/1.1 201 Created
   {cam@soldi.test, hunter222, "Cam Olechowski"}
   Set-Cookie: soldi_session=…; HttpOnly; SameSite=Lax; Max-Age=2592000
   {user.id: U_MPT9JLPC_…, displayHandle: CamOlechowsk7389,
    balance: 50000, heldBalance: 0, createdAt/lastActiveAt set}

$ curl /auth/me  (with cookie)      → {user: {…full profile…}}
$ curl /user/profile (with cookie)  → HTTP/1.1 200 OK

$ curl POST /auth/register {dup}    → HTTP/1.1 409 Conflict  {"error":"email_taken"}
$ curl POST /auth/login  {wrong pw} → HTTP/1.1 401 Unauthorized {"error":"invalid_credentials"}
$ curl POST /auth/login  {correct}  → HTTP/1.1 200 OK + Set-Cookie + updated last_active_at
$ curl POST /auth/logout            → HTTP/1.1 200 OK + Set-Cookie: …; Max-Age=0
$ curl /auth/me (post-logout)       → {"user":null}

$ curl /api/v1/auctions?status=all&limit=200  → count: 12 (slice 01 still green)
$ curl / and /login                 → HTTP/1.1 200 OK  (SPA + fallback intact)

$ wrangler d1 execute soldi --local --command \
    "SELECT type, amount, description FROM wallet_transactions WHERE user_id = 'U_…';"
  → {type: 'credit', amount: 50000, description: 'Welcome bonus'}

Gotcha caught during verify

Wrangler 3.114 no longer defaults wrangler dev to port 8788 — it picks a random ephemeral port (this run: 59545) and prints it in the boot banner. The first curl against the assumed 8788 failed ("Couldn't connect"). Pulled the port out of the wrangler stdout ([wrangler:inf] Ready on http://localhost:59545) before re-running the smoke battery. Worth pinning dev.port in wrangler.jsonc on a later polish slice so the port stops moving between runs.

Next up

Bidding — the slice that finally turns soldi into an auction house. Concretely: POST /api/v1/auctions/:id/bid with Zod-validated amount, PRD §8 increment table enforcement, balance + held-balance accounting (reserve the new highest bid, release the prior leader's hold), PRD §9 anti-snipe (+30s if the bid lands in the last 30s, capped at 12 extensions / 6 min), insert into bids, update auctions current_price / bid_count / end_time / snipe_extensions, and return the refreshed auction. Frontend: a bid input + submit on LeadDetail wired through the session, optimistic bid-history prepend, balance refresh, and error toasts for the failure modes (insufficient_funds, bid_too_low, auction_ended, unauthorized). Tests: a worker-side unit test for the increment + anti-snipe rules.

2026-06-09 — fhc-pages: Fast Home Cash landing page generator (launch-ready)

  • New tools/fhc-pages/: programmatic generator for fasthomecash.us — 51 state hubs + 200 city pages (incl. Chicago South Side / West Side / South Suburbs deep pages for the primary IL market), built with Bun + ETA + Zod, served by a dedicated Cloudflare Worker (port 8790, separate from the soldi app).
  • Lead capture: 3-step hero form + 2-step exit-intent popup, both POSTing occupancy/reason/listed_status + condition/timeline/ownership + TCPA consent
    • utm/landing-page tags to /api/offer-request. Meta Pixel + GA4 events wired (PageView → AddToCart → Lead).
  • Content: hand-written human-voice "Local Insight" for all IL/TX/FL pages; generated first drafts elsewhere. Hand-curated, visually-reviewed photography for the 24 focus pages; style-matched photo pools everywhere else.
  • bun run audit: launch gate checking SEO (unique titles/descriptions, canonicals, JSON-LD, sitemap), tracking, compliance links, TCPA consent, internal links, image liveness (--images), and brand safety (zero "Soldi" references — these pages must read as a standalone buyer).
  • docs/LAUNCH-PLAYBOOK.md: full Meta/Google/SEO/compliance launch sequence, incl. Housing special-ad-category handling and week-by-week first campaigns.
  • Deploy needs env vars (FHC_META_PIXEL_ID, FHC_GA4_ID, verification tags); audit blocks deploys with placeholder IDs. Not deployed yet — local verify only, per repo policy.

2026-07-07 — Wave-2 Bucket B: programmatic UI validation harness + all three user-facing surfaces green

  • Crash recovery: Docker VM died (disk full) mid-wave; all 16 local commits survived, orphaned work checkpointed, scratchpad Playwright env survived (rebuild recipe now in tools/ui-validate/README.md).
  • tools/ui-validate (B0): headless-Chromium harness — overflow / console / CLS / tap-target / chrome-height / computed-style assertions + screenshots, presets per surface, runs in-sandbox. Replaces "mac screenshot session" evidence with reproducible programmatic proofs.
  • App B3–B5 (B1): 32/32 assertions at 375×812 on Market/Leads/Territories/ Billing/Settings vs local wrangler dev (chrome 132px ≤ 150), scripted B4 drawer proof 8/8, B5 tablet/desktop clean → BETA_READINESS B3–B5 [MET]; D2 app-deploy decision now waits on Cam only. Found + fixed en route: session cookie hardcoded SameSite=None; Secure (dropped over local http; prod cookie byte-identical after fix, +4 tests, verify 249 green).
  • FHC responsive pass (B2): live 375px overflow on 4 template classes (+99px header CTA stack, +12px nowrap badges/CTAs), font-swap CLS 0.15–0.19, tap targets down to 21px → all fixed in templates/statics, empirically verified zero hit-area overlaps. Deployed: live fhc preset 133/133 (was 119/133; audit 0 blockers). Follow-up flagged: font preload net for display=optional.
  • Previews: agent-ads-ops font-swap CLS 0.31–0.35 → 0 via display=optional, deployed f7c0082d, live 15/15.

2026-07-10 (late night) — Zak's SEO PR #168 shipped + Meta pixel LIVE (PR #169)

  • PR #168 (Zak) merged + deployed: SEO waves 1-2 (robots Disallow /api/ + /collect, sitemap noindex cleanup, 301 /sell.html→/, per-state geo.region, city-meta dedupe, CLS/touch fixes) + 9 new content pages (/about, /resources hub + 5 guides, 2 comparison pages) + FAQ truth-sync. Gates: 549 pages, audit LAUNCH READY, firewall clean (only Soldiers Field). Live-verified: /about 200, robots + redirect + US-CO geo tag confirmed at edge.
  • GSC: Validate Fix started on Not found (404) + Blocked (4xx) buckets; homepage re-index requested (favicon nudge). Indexed 330 / not-indexed 25.
  • Meta pixel DONE: Cam created dataset "Fair Home Cash" 2141308983102237 (Velli business, Account Quality clean — no restriction found). Deployed via env, then PR #169 baked it as the metaPixelId build default (mirrors ga4Id). Live-verified fbq init on home/city/situation pages. Audit placeholder warnings gone. All FHC tracking IDs are now build defaults.

2026-07-10 (later) — CAPI + Google Ads conversion wired (PRs #170, #171)

  • Meta CAPI (PR #170): worker src/capi.ts sends server-side Lead to dataset 2141308983102237 (hashed em/ph/fn+ln-from-fullname/ct/zp/country + UA); every offer-form success path now generates a shared event_id (FormData + fbq eventID) so Meta dedups pixel vs CAPI; thank-you page-load Lead removed (was double- counting with submit-time Lead). Inert until META_CAPI_TOKEN secret is set — token generated in Events Manager, Cam pastes (agent guardrail blocks handling).
  • Google Ads conversion (PR #171): created "FHC - Offer Request" in the LIVE account 215-505-5201 (Submit lead form, primary, static $125, count one) and wired AW-18306794294/o0eXCJapnc4cELaGrplE into /thank-you. Live-verified. Blind-spend gap closed (campaign had only 1 impression since Jul 7).
  • GA4↔Ads: already linked Jul 7 (Completed, personalized ads enabled) — no action needed. EXPORT_KEY secret confirmed present. CID 445-354-3394 = stub, 215-505-5201 = live (conflict resolved).
  • AJ (Google rep) email logged: FHC must declare Housing category (limits audience targeting; customer match/remarketing/custom segments still OK); Demand Gen video suggested. Elite Flippers unreliable-claims warnings are Zak/Abdullah's lane.

2026-07-11 (early AM) — buyer-photo hotfix + polish + CAPI live (PRs #174, #175)

  • Zak's "broken" report: state/city buyer photos rendered 320x1200 strips — wave-2 width/height attrs became a UA height:1200px hint that beat the CSS aspect-ratio (width was overridden, height wasn't). Fix: height:auto on .buyer-photo in both templates (PR #174), live-verified 320x427.
  • Post-change polish (mandatory workflow) on both templates (PR #175): micro-interactions + simplify, reduced-motion guards, no new deps; gates green (549 pages, audit 0, app 264/264), deployed + edge-verified.
  • META_CAPI_TOKEN set — piped from Cam's 1Password item via op CLI straight into wrangler secret (token never entered the transcript). End-to-end verify: labeled test lead through live form → worker log shows _eventId stored, CAPI call ran, zero [capi] errors. EM chart lags ~30 min (and check the date range — picker was set to Jun 12–Jul 9, excludes today).
  • GBP guidance: business type = Service business only (visits customers, address hidden). Housing declaration: no self-serve UI exists — Google's classifier flags first; watch Admin → Policy → Ads.

2026-07-11 — Zak's Wave 3-4.5 loaded PR shipped (PR #176)

  • 912 pages live (540→912): 255 /es/ Spanish pages (reciprocal hreflang en/es/x-default verified live), 51 housing-market + 51 closing-cost data pages, glossary hub, property-type hubs, FB sameAs, 272 unique metas.
  • Worker: 9-tag lead taxonomy + junk-phone hardening (_suspect flag), soldi-ingest tax-delinquent mapping fix (occupancy/ownership no longer dropped), soft-lead nurture drip (Day 0 fires on enrollment NOW; Day 3/7 wait on a daily cron → /api/nurture-tick, Bearer EXPORT_KEY, 401 verified). ⚠ CAN-SPAM ops rule: reply-based unsubscribe — check the lead inbox daily while drips run. Cron wiring is Cam's call (options doc'd in src/nurture.ts).
  • Pre-merge verification: audit 0, firewall clean, and ALL of tonight's work preserved in the built output (pixel, AW tag, buyer-photo fix, sameAs).

2026-07-11 (PM) — Zak's scaled-content protection shipped (PR #177)

  • Google scaled-content-abuse mitigation: 300 boilerplate thin pages (inherited/divorce/fire-damaged families × 50 states × EN+ES) now noindex,follow + excluded from every sitemap. Reversible via THIN_TIER_REASONS flag in build.ts. Thin-flagged share of indexable pages 42.8% → 6.8% (Zak's shingle scanner).
  • Foreclosure family + IL funnel + all city/state/market/closing-cost/glossary/ hub pages UNTOUCHED and indexable (machine-verified both directions).
  • audit.ts hardened: noindex is now a hard blocker anywhere outside the thin families, with EN+ES sitemap-consistency gates — a future build can't silently noindex a hub/funnel page.
  • Closing-costs enriched ~150 → 640+ sourced words/page (masked similarity 1.0 → 0.45); TN/VT/MS/WY transfer-tax fixes.
  • Pre-merge verify: gates green (912 pages, audit 0/0), noindex placement audited (only thin+404+embed+legal+thank-you), tonight's tracking/fixes (pixel/AW/photo/hreflang/sameAs) all preserved. Live-verified: thin page 200+noindex+out-of-sitemap, money pages 200+indexable.

2026-07-12 — Zak's trust cluster + brand unification shipped (PR #178)

  • "Make it finished" batch (917 pages, 4 Fable-authored commits): 50 stop-foreclosure guides enriched 210 → 440-580 words (per-state statute/ redemption/timeline data from foreclosure-rules.ts); 6 new trust surfaces live — /reviews (zero fake stars), /is-fair-home-cash-legit, /avoiding- we-buy-houses-scams, /sellers-bill-of-rights (site-wide footer link), /transaction-history (noindex proof ledger), 3-way net table on /how-we-make-offers. "Your numbers in {State}" cost strips on all 50 states.
  • Brand unification: ONE canonical house+door logo on 915/918 pages (+ logo.svg schema asset); og:image + twitter cards + apple-touch-icon site-wide; llms.txt trust pages.
  • Premium EN↔ES toggle v2 (View Transitions API): imagery frozen across the swap (browser-measured height delta 0, zero src changes), pill glide, reduced-motion instant, 62/62 form radios survive.
  • 3 new permanent audit gates: shingle-similarity thin-page gate (boilerplate can't ship again), brand-invariants gate (logo signature/og:image/apple- touch/aspect-ratio-height-auto), merge-leak detection — all negative-tested.
  • Pre-merge verify: gates green (build 917, audit 0/0 + new gates), firewall clean (only "Soldiers Field"), diff 48 files all FHC-scoped (no secrets). #177 protection intact (50 non-IL states × 3 families still noindex + out of sitemap; IL enriched as money market). Live-verified: 4 trust pages 200, /reviews "Zero Fake", enriched TX guide 200 w/ statute content, thin page 200+noindex, logo.svg + apple-touch-icon 200. Deploy: worker uploaded (route- attach 401 benign, routes pre-exist), new pages confirmed live at edge.
  • Completes AJ's "landing pages squared away" gate → ads relaunch unblocked (RSA pack is with Zak).

2026-07-13 — PR #199 identity-copy rereview repair ready (not deployed)

  • Replaced PR #199's new direct-principal wording (Fair Home Cash makes..., we are a "we buy houses" operation, property-specific we buy...) with neutral seller-benefit copy: request/get written cash offers, no fees, and a seller-controlled decision. EN, authored ES, visible FAQ, JSON-LD, statics, and generated template mirrors were updated together.
  • Removed previously missed connector mechanics from non-disclosure calculator, market, closing-cost, and Illinois-situation pages. About, Privacy, Terms, and is-fair-home-cash-legit remain the sanctioned disclosure layer and were not edited. Lead forms, consent, /api/offer-request, ingest, and nurture behavior were unchanged.
  • Replaced the non-recursive 630-pageFiles copy check with a shared policy that scans all 941 built HTML artifacts, including registered statics and 255 ES twins, across visible, JSON-LD, and meta/OG layers. Added 16 negative/allowance fixtures for EN, ES, FHC, static/generated layers, and disclosure carve-outs.
  • Post-merge verification: bun test in sites/fhc-pages 19/19 (16 policy + 3 ingest); bun run build:fhc 940 pages / 255 ES twins; bun run audit 0 blockers, 0 warnings with recursive copy count 941; root bun run verify 37 files / 354 tests + production build; no PR-relative lead-form behavior diff; FHC Soldi firewall clean; git diff --check clean.
  • Current-main proof: fetched origin/main at exact SHA d2d8173 (merged PR #161) and preserved both histories in merge commit 9c48345 (parents 27ff137 + d2d8173) before the post-merge gates above. Root verify emitted one non-blocking duplicate React key warning from the current-main Territories.test.tsx; all 354 assertions passed.
  • Durable copy handoff: complete C01-C34 before/after ledger plus A01-A04 audit message deltas at docs/implementation-notes/fhc-copy-identity-audit-ledger.md; root-operator twin at /tmp/soldi-v60-20260713-pr199-copy-delta.md.
  • No deploy was run. Root owns rereview, deploy, live proof, and the post-deploy text to Zak.

2026-07-12 — Zak's intelligence wave shipped (PR #179)

  • Data-first wave (931 pages, 3 commits): built off real distress data (DePaul-IHS / ILFLS / ATTOM / Cook Pappas) + live SERP analysis so pages target where foreclosure distress and search demand actually overlap.
  • Chicago intent cluster (4 pages, 1,900-2,300w, 1.7-3.5% overlap): /cash-home-buyers-chicago, /sell-house-as-is-chicago, /sell-house-fast- chicago-suburbs (re-aimed at southern Cook), /we-buy-condos-chicago. Ads note: repoint the we-buy-houses ad group here, NOT the national homepage.
  • 4 collar-county foreclosure-timeline hubs (Will/Kane/Lake/DuPage) with county-real mediation/court facts (honest DuPage no-mediation note); south- suburb seller pages Harvey/Dolton/Calumet City (Cook tax-delinquency moat: scavenger sale, 38,765 forfeited certificates, sale-in-error losses, cited).
  • /illinois-foreclosure-timeline: 3,236w staged article (the format that wins "how long does foreclosure take in illinois"), funnels into the calculator. Roundups upgraded to named entries + published methodology.
  • Money-market re-index: 'inherited' family REMOVED from thin-tier noindex after passing the validation scanner (median 352 est-unique words ≥ 300, masked-Jaccard 0.835 ≤ 0.85) → +100 indexable pages, now in sitemaps. 'divorce' re-scanned same day and FAILED (285uw / 0.878) → stays noindex+ out-of-sitemap until a researched legal layer earns it. Thin tiers 300→200.
  • New permanent audit gate: static-page substance floor (every indexable static ≥ 400 visible words + exactly 1 h1 + canonical) — closes the blind spot where Phase-B statics bypassed all content gates.
  • Pre-merge verify: gates green (build 931, audit 0/0 LAUNCH READY, 90 pages shingle-diffed incl. now-indexable inherited), firewall clean, diff 31 files all FHC-scoped (no secrets/internal). Live-verified at edge: 14 new pages 200 w/ full content + single h1 + index,follow; inherited TX index,follow +in- sitemap, divorce TX noindex +out; IL timeline article live; logo + apple- touch 200. Deploy: worker uploaded (route-attach 401 benign, routes pre- exist). Zak runs the GSC request-indexing plan on the new pages next.

2026-07-13 — Zak's parity + mobile + photos wave shipped (PR #194)

Third FHC wave off the same feat/fhc-seo-wave3 branch (re-synced on main after #179). 75 files, +2343/-149, three commits. Build 940 pages, audit 0/0 LAUNCH READY. Merged bc66503, deployed + edge-verified.

  • Parity wave (fb9e2ee): we-buy-houses keyword family — /we-buy-houses- chicago (3252w), /we-buy-houses-illinois (3033w), /we-buy-houses-near-me (3009w) — owns the 2nd keyword family competitors split across two brands. 6 indexed single-question FAQ pages (faq-*.html) w/ valid QAPage structured data (Question + acceptedAnswer + mainEntity) targeting question SERPs. Published offer range (up to 85% of market value) + Fair Offer Guarantee on /how-we-make-offers — the TPBC "publish your math" play. Proof-ledger anatomy on /transaction-history, stays noindex,follow until deal #1.
  • Mobile perfection pass (5a404df): 22 CSS/template fixes from a 2-inspector 390px + 360px phone audit + end-to-end thumb-test of the money flow. HIGH: closing-costs calculator card overflow (min-width:0), invisible ES toggle knob on cold /es/ loads, ES cost table rendering in English, 16px input floor (kills iOS focus-zoom on the address field — verified 9 inputs @16px on state pages), scroll-padding-top so wizard Qs clear the sticky header. All CSS-level; form logic untouched — money flow verified intact (offerForm, 9 reason radios, gclid all present on sell-my-house-fast-illinois).
  • Self-hosted Chicago photos (9b40061): 17 license-verified images now served from /images/ (hero-chicago-rooftops, aerial-logan-square, two-flats, etc.); IL/Chicago/national heroes + /offer swapped off hotlinked Unsplash → faster LCP + Google Images eligibility. audit.ts gained an asset-href gate (any /images/*.jpg href must resolve in dist, else BLOCKER) — negative-tested, all 17 resolve. New FHC_REVIEW_COUNTS env (analytics.env.example): review strip is stripped from dist while unset → no fabricated review counts ever ship (verified: reviews page shows zero visible counts).
  • Pre-merge verify: build 940 exit 0, audit 0/0 (asset-gate + 9 new statics now under the ≥400w substance floor, still 0 blockers), firewall clean (shipped dist Soldi-free), diff 75 files all FHC-scoped no secrets, both flagged JS items confirmed untouched. Edge-verified: 3 we-buy-houses pages + 6 FAQ pages
    • how-we-make-offers all 200 w/ full content + 1 h1 + index,follow (2 FAQ pages caught mid-propagation across PoPs, settled on recheck); self-hosted heroes 200; transaction-history noindex; reviews honest. Deploy: 951 files uploaded (route-attach 401 benign as always).
  • Left for Cam's call (JS-level, Zak deliberately untouched): (1) mid-wizard sticky "Get My Cash Offer" bar targets the hidden address field → dead tap; fix = retarget or hide during wizard. (2) localhost testing fires real GA4/Meta pixel events → one-line hostname guard keeps test noise out of funnel data. (3) Non-blocking follow-up I flagged: 581 templated pages (closing-costs
    • non-IL states) still hotlink images.unsplash.com — pre-existing, the swap only covered the approved Chicago/IL heroes.
  • Zak's next: GSC request-indexing on the 9 new URLs + the launch kit (HARO, video, profiles, RSA relaunch → repoint we-buy-houses ad group to /cash-home-buyers-chicago). Cam's outstanding: www DNS + Always-HTTPS toggle.
  • PR #193 (buyer marketplace v60, app money surface) intentionally NOT merged/deployed here — frontend-complete but backend-stubbed, overlaps Cam's own open #180 (payments/lead-import). Held for Cam's sequencing call.

2026-07-13 — PR #193 merged + PR #194 flagged items fixed (PR #195)

Same-day follow-through on Cam's calls from the #193/#194 review.

  • PR #193 merged (e4727f1) per Cam: land Zak's v60 frontend now, integrate the real backend on top next. Post-merge bun run verify went RED — 5 Billing tests (localStorage.clear is not a function): vitest's jsdom env exposes localStorage as a bare object with no Storage methods, and #193's new Billing.test.tsx (green on its old base) assumed jsdom provided one. Fixed with a self-contained localStorage stub in Billing.test.tsx mirroring BuyerScreens (d22c9d5). Main green again: typecheck + 354 tests + build, exit 0. Handoff prompt for the backend-integration agent written to docs/notes/marketplace-backend-integration-handoff.md (money model = app/shared/marketplace-rules.ts; stubs = app/src/lib/api/{package,market,leads}.ts; harvest Cam's #180 + Stripe branches; note HANDOFF.md isn't in-repo, spec lives in docs/implementation-notes/mkt-*.md).
  • PR #195 shipped (73c1bf2) — the two items Zak flagged for Cam in #194:
    1. Non-prod analytics guard — new partials/notrack-guard.eta, included before the Meta Pixel in all 7 page templates. On non-prod hosts (localhost / preview / *.workers.dev) it sets the GA4 + Google Ads ga-disable opt-out flags, pre-stubs fbq so the Meta bootstrap bails (no pixel / PageView), and flags the first-party beacon (__FHC_NOTRACK/collect POST in partials/analytics.eta no-ops). The guard branches at runtime on location.hostname; the shipped HTML is identical everywhere, so prod (fairhomecash.com) early-returns and tracking fires untouched.
    2. Sticky CTA dead-tapcity-page.eta: syncSticky() hides #stickyCta while the wizard is past step 1 (the 'Get My Cash Offer' bar was focusing the hidden #address field). Hooked into showStep + init. Form logic + money flow untouched.
  • Gates: build 940, audit 0/0 LAUNCH READY, firewall clean (new partial Soldi-free), money flow intact (offerForm + 9 reason radios). Deployed + edge-verified: guard present (ga-disable ×2) + prod IDs live (GA4 G-3553MET586, Meta 2141308983102237, fbq init, gtag config) on state + city pages; sticky fix live on city pages (syncSticky ×3, onStep1). Deploy: 886 files uploaded (route-attach 401 benign).
  • Still open (non-blocking): 581 templated pages (closing-costs + non-IL states) still hotlink images.unsplash.com — pre-existing; #194's swap covered only the approved Chicago/IL heroes. Flagged to Zak as a follow-up.

2026-07-13 — Marketplace v60 Phase 0 alignment gate

  • Reconciled the attached v60 handoff, the byte-identical marketplace mock twins, current main at 9a1b7fa, migrations 0001–0024, the shared marketplace rules, and the diverged PR #180 integration branch.
  • Published docs/plans/marketplace-v60-alignment-matrix.md with all six screens classified as mock/app/real-or-stub/verdict, plus dependency-safe implementation slices.
  • Found a blocking economic-spec contradiction: the checked-in mock has $500 editable funding, auto-reload, and a $1,500 activation deposit, but no Package/bonus/tier system; the handoff requires $1,000 minimum funding, bonus tiers, Warm/Hot/Cold pricing, and a real $5,000 Package while also saying the mock wins.
  • Parked buyer auction UI, buyer manual lead entry, recurring Package automation, and expanded refund automation in the roadmap without deleting load-bearing auction persistence, Admin supply intake, or the current refund request path.
  • Verification before and after Phase 0: bun install && bun run verify passed 37 test files / 354 tests, TypeScript, and Vite build assets/index-CPWAyJ6J.js; bun run build:docs built 10 internal + 2 client docs + index. The pre-existing duplicate SO_1 React-key warning remains in the Territories test. No product code, migration, remote operation, Stripe operation, or deploy ran.
  • Next up: owner selects the economic-spec authority and Package charge model; then replay Stripe economic-intent integrity as the first independently proven backend slice.

2026-07-13 — Marketplace v60 provenance correction and unblock

  • Reopened the Phase 0 gate after the owner clarified that Zak had just demonstrated Package plus Hot/Warm/Cold. GitHub and Git history proved that the preview files on main were stale at July 5, while Zak's PR #161 advanced the same two files through v40/v41/v44/v45 to build v60 at f8b192b on July 13.
  • PR #161's v60 comment explicitly supersedes prior versions and points to Zak-authored, merged PR #193 (e4727f1) as the real-app port. The current product contract is therefore Cold $90 / Warm $150 / Hot $250, $1,000 minimum funding with $100/$300 bonuses, $5,000 wallet-funded Package for 25 delivered Hot leads at $200, and $150+ tier-covering Territory bids.
  • Merged PR #161's eight-commit two-file preview lineage into the launch train. Both twins are 2,518 lines, byte-identical, stamped build v60, and SHA-256 fbe6ed23b8507617a910068f3c1c3e7ca1293af80ea67fcee1bc4e687938c58c.
  • Resolved Package activation to an atomic server-side wallet debit after separately proven Stripe wallet funding. No dedicated Package Checkout will be invented.
  • Corrected docs/plans/marketplace-v60-alignment-matrix.md, the roadmap, and implementation notes. No app runtime code, migration, Stripe operation, remote service, or deploy changed in this correction.
  • Verification: bun run verify passed 37 files / 354 tests, TypeScript, and Vite assets/index-CPWAyJ6J.js; merged preview inline JavaScript passed node --check; twins passed cmp; git diff --check passed. The pre-existing duplicate SO_1 Territories test warning remains. There is no root build:previews script.
  • Next up: Stripe economic-intent integrity as the first focused PR into master #196, followed by canonical acquisition and atomic Market purchase.

2026-07-13 - PR #198 Terra P1 Territory handoff correction

  • Preserved pending-only FHC and raw source provenance, but changed approved/priced exact Admin classification to claim and run the retained Territory priority allocator before a true no-match becomes Open Market inventory. Shared territoryBidCanClaimLead enforces $150 coverage for Cold/Warm and $250 for Hot; the deleted buyer-facing auto-buy UI remains deleted.
  • Added migration 0027_territory_allocation_claims.sql for one leased/tokenized allocation owner and unique sold portfolio/ledger outcomes. Processing, finalizing, and debited crash states resume with the persisted review ID; debit/cap/state transitions are one D1 batch; final lead/claim CAS and every counter/ledger/portfolio/delivery write require the same token. A durable inconsistent committing state fails closed for operator repair.
  • Restored reachable end-to-end economics tests: no-match availability, guarded-debit failure, cap-race refund, concurrent/repeated Admin review, exactly-once sold delivery, crash recovery before/after debit, and token takeover immediately before finalization with zero stale-owner writes.
  • Evidence: focused Territory/Admin/ingest/rules suite 159/159; fresh disposable local D1 migrations 00010027 succeeded and lead_allocation_claims schema was queried; full bun run verify passed 39 files / 380 tests, TypeScript, and Vite assets/index-LfcA747C.js; bun run build:docs and git diff --check passed. Only the pre-existing duplicate SO_1 Territories test-key and bundle-size warnings remained. No deployment, remote D1/Stripe write, or secret access ran.
  • Next: Terra/high rereview of PR #198, then keep direct Market purchase and later economic planes isolated.

2026-07-14 — Marketplace v60 live-readiness consolidation

  • Mined Codex sessions 019f5ee8-88d9-7ef3-a1ce-d250debb4fd7 and 019f5cc3-299b-7ee3-b92d-b1ea06034c4f, then reconciled the generated findings against current PR metadata, exact branch heads, deployments, source, and Zak's latest iMessage. The repeated third session ID was a duplicate.
  • Corrected the generated synthesis: PR #198 is complete, exact-head Terra-approved at 548736e, and integrated into master PR #196. PR #196 is ready/non-draft, clean, and CI-green at 3c997b5.
  • Reclassified PR #180 as a semantic source rather than a merge candidate. It is conflicting against a pre-v60 base, but contains independently reviewed Market transaction, Admin CSV/import-integrity, refund-integrity, exact-SHA health, staging-control, and browser-harness seams. Ports must preserve #197/#198, start migrations after current 0027, and land as focused ready PRs to #196.
  • Confirmed new work still required: distinct purchased/promo credit accounting and a persisted wallet-funded Package lifecycle. Confirmed Territory $150 plus tier-coverage enforcement already exists and needs an end-to-end audit/closure rather than a rebuild.
  • Confirmed hosted truth remains NO-GO: staging.soldi.cc does not resolve, the existing isolated staging D1 is not a deployed environment, current /health returns SPA HTML, and app.soldi.cc predates #196.
  • Confirmed FHC PR #199 moved after R6 to Zak head 8eba975; its body/copy ledger are stale and require current-head reconciliation, full gates, independent review, merge, deploy, and live proof. Sent Zak a verified acknowledgment that names the exact head and promises explicit copy accounting plus post-deploy proof; no live claim was made.
  • Published the complete operator synthesis and queue prompts at /tmp/mine-codex/soldi-live-readiness/INSIGHTS.md and refreshed the marketplace v60 implementation note/index/roadmap. No product code, migration, remote database, Stripe mutation, merge, or deploy occurred; no walkthrough screenshot changed because no deployed product state changed.
  • Verification at #196 head 3c997b5: bun install --frozen-lockfile made no changes; bun run verify passed 39 files / 381 tests, TypeScript, and Vite assets/index-LfcA747C.js. Expected forced Territory failure stderr, duplicate SO_1 key warning, and Vite bundle advisory remain non-failing diagnostics.
  • Next: release FHC #199 at one reviewed exact head; merge resulting main into #196; port Market purchase, Admin CSV, and refund seams; implement promo/Package economics; then provision protected cron-off staging and run four reset-isolated Sol/Terra desktop/mobile receipts before production.

2026-07-14 — Marketplace v60 hosted security boundary

  • Added exact same-origin CORS and defense-in-depth CSRF for cookie-authenticated unsafe methods. Login/register remain unauthenticated bootstrap routes; Stripe webhook and FHC ingest retain their signed server-to-server boundaries. Existing sessions receive a session-derived CSRF companion cookie from /auth/me.
  • Removed hosted fixture fail-open behavior: missing Stripe configuration returns 503 instead of minting wallet funds, and missing FHC_INGEST_SECRET returns 503 instead of accepting unsigned leads. Both fixtures remain available only on localhost development requests.
  • Upgraded Hono from ^4.6.14 to ^4.12.25 (lockfile 4.12.30), clearing the direct Hono runtime advisory. Remaining bun audit findings belong to the Vitest/jsdom/Vite development chain; do not expose dev servers.
  • Full bun run verify passed 41 files / 400 tests, TypeScript, and Vite assets/index-COujzqxe.js; bun run build:docs and git diff --check passed. Route-level proof now covers cross-origin login/register with an existing session, same-origin tokenized bootstrap, old-session CSRF refresh, invalid/expired-session login recovery, signed Stripe/FHC exemptions, same-origin preflight, and both auth cookies. The transport-only Comps.parts.tsx change has no rendered UI delta; tmx exact-head polish/security rereview is the publication gate.
  • Next: publish a ready child PR to #196, request Zak, merge after QA, then close atomic Market purchase before wallet subledgers, import/refund, and Package renewal.
  • Terra/high exact-commit review rejected the first candidate on login CSRF and deck truth: login/register bypassed the global guard entirely, allowing cross-origin session replacement, and the deck marked undeployed train behavior live. The corrected guard applies exact Origin/Referer to all browser mutations, permits tokenless same-origin bootstrap only before a session exists, and preserves signed Stripe/FHC server exemptions. Focused security/payment/ingest/client tests now pass 18/18; the walkthrough uses an amber plan badge and explicitly separates current production from the undeployed train.

2026-07-14 — PR #199 newest-head reconciliation before release

  • Rebased the release work normally onto Zak's newest 43ca26f best-site wave. Preserved the 18 new FAQ pages, 50-state selling-cost report, local photo catalog, calculator embeds, 102 re-indexed EN/ES divorce pages, six Chicago neighborhood pages, and favicon work as the source base.
  • Corrected the now-confirmed mixed business model in About, Privacy, Terms, and legitimacy copy: Fair Home Cash may buy a qualifying house directly or may involve an independent buyer, and it is the buyer only when named in the purchase contract. Direct we buy language remains valid.
  • Qualified unconditional offer outcomes across generated city/state/national copy and authored public pages. If the property is a fit, you may receive replaces universal you get/comes back results; the 24-hour offer aspiration remains conditional. Zak's newest changes are C50-C54; owner-directed changes are C55-C59/A12.
  • Replaced the obsolete never-a-buyer classifier with a mixed-model policy: connector mechanics remain blocked outside disclosure pages, while universal purchase/offer guarantees and fabricated track record remain blocked everywhere relevant.
  • Sol/medium's immutable raw-head review rejected 43ca26f on three P1s and one adjacent P2: third-party embed snippets were defeated by global X-Frame-Options: SAMEORIGIN; the authored Illinois calculator full form displayed click-consent but submitted no consent field, so signed Soldi forwarding dropped it; public disclosures and llms.txt described incompatible models; and embed mode hid nonexistent .rel-links instead of the real .xlinks block.
  • Corrected all four above Zak's intact wave. Explicit embed responses now use frame-ancestors * without XFO while ordinary pages retain SAMEORIGIN; embed topbar/related links are hidden; Illinois offer submissions carry consent/source provenance; llms.txt uses the same conditional mixed model as the legal pages (C59).
  • Sol/medium's first corrected-head review rejected aabdb98 on two more P1s plus one ledger P2: any ordinary route could become frameable by appending ?embed=1, and 24 FAQ plus 51 state-page results still promised an offer. The final correction restricts the frame exception to real calculator routes, tests the negative path, conditions the complete missed offer corpus, strengthens exact grammar fixtures, and scopes the stale ledger claim as historical. These changes are C60-C63/A13.
  • Sol/medium's 3b3754d rereview closed those exact findings but rejected the still-unrecognized automatic-offer results in /offer, all state heroes, form success states, and residual authored pages. C64/A14 conditions the full EN/ES result corpus and teaches the recursive audit the exact we make, expect ... with your offer, and offer arrives bypasses; the stronger audit then surfaced and closed three adjacent authored statements.
  • Sol's next exact-head pass approved the complete result corpus with no P0/P1 and identified one localized /offer reassurance P2. The sentence now preserves the real decision order: request a review; if an offer is received, then decide.
  • Evidence so far: focused FHC/ingest/embed tests 42/42; build 965 pages / 255 Spanish; recursive audit 966 HTML with 0 blockers / 0 warnings; root verify 37 files / 354 tests plus TypeScript/Vite; docs build and diff check green. Final immutable-head tmx review, normal push, PR-body refresh, merge, deploy, live proof, and Zak C55-C64 copy notification remain before the release is complete.

2026-07-15 — v60 Admin import and Package routing child (local proof complete; not deployed)

  • Started at exact 9a9525fd26095b0f4e98403a6bac4dd275cd05a0 in the isolated codex/v60-admin-import-package-routing worktree. Added an initial 0031_admin_import_package_router.sql draft, strict 24-column Admin CSV parser/route, immutable raw-CSV idempotency receipt, NFKC identity fence, and persisted disabled-routing decision before a no-match becomes Market availability.
  • package_fulfillment_state remains untouched and no 0032 exists. The unresolved supply-reserve ratio and no staged caller proof keep activation/renewal fail-closed.
  • Replaced the stale JavaScript candidate authority with one Package D1 batch whose first INSERT ... SELECT persists the deterministic eligible buyer reservation; fulfillment claim, sold lead, portfolio/stage/delivery, Package delivery, exact cycle/user counters, completion guards, resolved_channel='package', and immutable terminal receipt follow from that reservation. The identical SQL predicate is re-used by an immutable Market-fallback reservation, preventing Market availability while a qualifying Package buyer exists. No Package wallet or buyer-budget debit occurs.
  • Admin imports now use pending/completed batch receipts with counted identity/consent/audit/row completion enforcement, immutable batch/row/identity receipts, raw source plus canonical acquisition, NFKC duplicate detection, idempotency replay/conflict handling, and all-or-nothing D1 writes. 0030 was restored byte-for-byte after a migration-immutability correction; resolved_channel remains exclusively in new 0031, with a pre-0031 Territory compatibility fallback.
  • Evidence: fresh local migrations 00010031; parser plus real-SQLite Package routing/upgrade, two-buyer fairness, concurrent replay, Admin import route, and Idempotency-Key boundary suites passed; full bun run verify 58 files / 539 tests, TypeScript, and Vite build assets/index-B3nOIi7c.js; bun run build:docs; git diff --check; and touched TypeScript line audit all passed. Expected forced rollback/compensation stderr and the existing duplicate SO_1 React-key warning remain non-failing test diagnostics. No remote mutation, commit, push, or deploy occurred.

2026-07-15 — v60 six-screen final local acceptance corrections

  • Preserved Zak's pinned v60 mock as the visual/token authority and kept staging/promotion frozen. The second exact-range review rejected stale zoomed Settings/Territories receipts and residual public em-dash copy; both mobile receipts were recaptured at true 390px width, the browser title now uses the mock's middle dot, and the Worker transaction presentation boundary normalizes historical em dashes to colons without rewriting ledger rows.
  • Root original-resolution review rejected the first replacement Transactions mobile receipt even though the automated geometry lane accepted it: Territory attribution stacked vertically, Resend overlapped it, and amount/balance clipped. The row now uses the mock's equal two-column mobile grid, keeps attribution and money in separate tracks, and places actions on a dedicated full-width row while preserving the desktop flex composition and existing v60 tokens.
  • Independent Sol/medium browser proof measured two equal 155px tracks at 390px, one-line Territory attribution, zero overlap, fully contained amount/balance, 390/390 page width, no console errors, no forbidden checklist vocabulary, and no public em dash. Root re-inspected the 390×844 and 1440×900 PNGs at original resolution and accepted them.
  • Final local gate passed 67 files / 586 tests, TypeScript, Vite assets/index-BiQwcHs_.js, 10 internal + 2 client docs + index, git diff --check, and the strict <400 touched-source rule. No deploy, remote database mutation, Stripe mutation, or production claim occurred.
  • Next: commit one immutable head; require fresh full-range Sol/medium and Terra/high zero-finding verdicts; then open the single ready PR into the launch train, request killerabbasi, send Zak the two added punctuation deltas, merge after QA, and keep staging as the next separate promotion gate.
  • Immutable R5 rejected acf40c9 on three stale/zoomed desktop receipts and contradictory Territory transaction detail. Sol otherwise found no code/API/security/money/taxonomy defect. Terra's additional public-auction-API finding was false and formally withdrawn after app/worker/index.ts plus the exact 404 worker test were rechecked.
  • Payment & Budget, Settings, and Territories desktop evidence was replaced at true 1440px CSS scale. Root caught and rejected a browser-selection race that briefly put Open Market into the Settings PNG, then used a new isolated context to prove route, H1, DPR/scale, 1440/1440 width, fonts, API readiness, copy, and console state immediately before the accepted Settings/Territories writes.
  • Standing-order transactions now project generic Territory lead detail and use the joined lead only for via your X County territory, preventing contradictory historical county text without mutating immutable ledger storage. Unit, real-SQLite, component, and desktop/mobile browser proof cover the mismatch and clean two-column geometry.
  • Reconciled the apparent four-situation/Agent conflict by the checklist's own authority declaration: the named byte-identical v60 mock is the acceptance standard and deliberately implements Agent listing-intent tabs, so "4 ONLY" governs Investor mode rather than deleting the mock-backed Agent branch. Zak was asked to correct this interpretation during PR review if needed.
  • R6 full gate passed 67 files / 588 tests, TypeScript, Vite assets/index-BiQwcHs_.js, 10 internal + 2 client docs + index, diff/secret hygiene, and the strict <400 changed-source rule. No deployment, remote database mutation, Stripe mutation, or hosted claim occurred.
  • Final all-12 root inspection caught the accepted Territories desktop receipt at a nonzero horizontal scroll position even though its document-width assertion was clean. It was recaptured at explicit scrollX=0 after route/H1, 1440×900 viewport, DPR 1, 1440/1440 width, loaded-font, forbidden-copy, and console checks; the replacement was re-inspected at original resolution.
  • Ready PR #210 opened at 2e3fbf0, requested Zak, and disclosed the complete copy/functional delta plus Agent-mode interpretation before merge. The child exposed no GitHub checks, so it merged after the exact local gate as launch-train head 0552cc2; master PR #196's body was reconciled and its changes, FHC audit when changed, and bun verify checks passed. No deployment or remote service mutation occurred.

2026-07-15 — Marketplace v60 backend integrity adversarial correction

  • Reopened codex/v60-marketplace-backend-integrity after reviewer reproduction: production accepted the newly seeded fictional contact 48 Juniper Lane / Avery Collins / +1-202-555-0175 because only legacy placeholder fragments were guarded. The shared guard now rejects all six normalized v60 address/name/phone triples only when all three fields match, covering signed FHC ingest, Admin manual entry, Admin CSV import, and a post-seed D1 BEFORE INSERT trigger. This is fictional test data only; no real personal data was added.
  • Extended the existing backend 0032_v60_data_integrity.sql (no new migration number) to recompute non-null leads.territory_distress_key after taxonomy conversion and to rebuild non-null, structurally safe standing_orders.filter_match_json from rewritten filter_json. This closes the reviewer P1 where a migrated Probate order and a new Inherited order could land in separate Territory RANK() partitions and both display position 1. Null unsafe-history keys remain fail closed.
  • Regression evidence: the focused production-guard / ingress / real-SQLite migration suite passed 5 files / 66 tests, including all six markers in every ingress path and direct D1 writes; its Territory route regression proves migrated/new Inherited orders report positions 1 and 2. A fresh disposable local D1 applied migrations 00010032 and returned zero legacy placeholders, six v60 seed leads, three typed purchases, 451,000 balance cents, 49,000 purchase-debit cents, zero activation rows, and zero stale probate lead/match keys. Root bun run verify passed 69 files / 624 tests, TypeScript, and Vite assets/index-BdJy0tCO.js; bun run build:docs and git diff --check passed. Expected forced rollback stderr from existing Admin-import idempotency tests and the Vite chunk-size advisory remain non-failing. No deploy, remote D1 change, Stripe operation, PR, or merge occurred.
  • Next: commit/push this correction, preserve backend 0032, and have the package branch rebase and claim 0033 after backend merge.

2026-07-15 — Marketplace v60 production fixture-exposure P0 closure

  • Reviewer correctly found that rejecting future fixture writes did not protect the six fictional leads inserted by 0032 itself. The Market route now excludes their canonical migration IDs from list/count results outside explicit fixture environments, rejects direct buy requests before any account/claim/ledger write, and repeats the exclusion in the atomic claim/purchase SQL.
  • Wrangler production has no APP_ENVIRONMENT variable while staging explicitly declares one. The guard now permits fixture data only for explicit development, test, or staging; undefined, production, and unknown values fail closed. The production config deliberately remains unset so a missing binding cannot make fixtures sellable. No environment-file values were read into this record.
  • Focused direct proof against a fully migrated SQLite database passed for both explicit production and undefined binding: Market listed zero fixture rows, a direct fixture buy returned 409 lead_unavailable, market_purchases remained zero for the fixture, and the buyer balance did not change. Focused fixture/ingress/Market tests passed 7 files / 81 tests; root bun run verify passed 69 files / 627 tests, TypeScript, and Vite assets/index-BdJy0tCO.js. The prior fresh disposable local D1 00010032 migration invariants remain unchanged because this P0 closes runtime exposure/claim boundaries rather than changing migration content. Expected forced rollback/resilience stderr and the Vite chunk-size advisory remain non-failing. No deploy, remote database mutation, Stripe operation, PR, or merge occurred.

2026-07-16 — Marketplace v60 buyer API quality-score P2 cleanup

  • Exact-head review found optional qualityScore still present in buyer-facing response contracts despite the Worker DTOs omitting it. Removed the residue from PipelineCard, OwnedLead, and MarketLead, and removed the typed buyer fixture values. LeadDossier keeps its existing breakdown visualization but no longer renders a nonexistent numeric score.
  • Scope stayed intentionally narrow: no Package pricing seam, migration number/content, Admin API contract, environment binding, deployment, PR, or remote mutation changed. Focused buyer API/mapper/route/component proof passed 8 files / 36 tests with TypeScript; root bun run verify passed 69 files / 627 tests, TypeScript, and Vite assets/index-BYdWsLVy.js; bun run build:docs and git diff --check passed.

2026-07-16 — v60 mobile-primary UI follow-up (local only)

  • Recorded Zak's nine 390px mobile gates in the parity checklist, MVP readiness control, QA matrix, implementation index/note, and exact copy delta. Desktop remains the f8b192b parity surface; no PR, deployment, or message to Zak occurred.
  • At <=640px, Open Market renders true cards with bottom-row Buy actions; My Leads uses labeled one-tap stage pills and direct ?lead= routing; seller numbers/emails are tel:/mailto: links; drawers, refund, Package, and Territory dialogs are bottom sheets; mobile controls meet 44px and confirm areas remain sticky. Root visual QA caught the dossier footer gap and it was corrected before closure with sticky Call seller plus direct stage pills.
  • Local browser proof used fresh exact-worktree sessions: Worker 8793 (local staging D1 after migrations 00010034, SESSION_SECRET loaded from the designated ignored source) and Vite 5183 with explicit API proxy. The six refreshed 390×844 captures live under docs/shots/v60-*-mobile-20260716.png; v60-refund-mobile-20260716.png adds the refund-sheet record. Browser checks observed 390/390 document width, three mobile Market cards with desktop table hidden, deep-link drawer, direct phone/email links, six sticky footer pills, and no horizontal overflow. This is local staging-fixture evidence, not hosted proof.
  • Performance: React route lazy boundaries reduced the initial Vite entry to 422.09 kB / 133.84 kB gzip; Leaflet remains deferred at 150.05 kB / 43.59 kB gzip. The owner prohibited internal subagents, so post-change-polish.js was intentionally not invoked; the implementation note records the solo four-lens make-it-sexy and make-it-simpler review for every changed production TSX.
  • Territory visual QA rejected the empty 0 of 0 capture. A strictly local staging fixture was created through the authenticated local Worker helper (201); the replacement v60-territories-mobile-20260716.png shows a populated 390×844 bid sheet (3 leads · 30d, $175, cap 4, worst case $700/week) and its sticky Add territory confirmation. The global help widget had intercepted that action through a parent stacking context, so TerritoryModal now portals to document.body; runtime proof has scrollWidth: 390 and the bottom-right hit target is Add territory, not help. The original literal staging Worker correctly rejected the Vite proxy with 403 csrf_origin_rejected. Owner-directed harness-only retry stopped that Worker and relaunched the same local D1 process with bun run dev:worker -- --port 8793 --env staging --var APP_ENVIRONMENT:development; after browser re-auth, the same visible UI POST returned 201, closed the sheet, added a third local order, and showed existing toast Territory added / NJ Pre-foreclosure is active. (v60-territories-mobile-success-20260716.png). No source/security config, migration, remote D1, deployment, or hosted claim changed; this is local development-origin evidence only.

2026-07-16 — Final v60 UI normal train integration (local verification pending)

  • Started from pushed UI/refund candidate 2afc8083c7d18b63a5539c02d23dc311c241fc51, fetched origin/orchestrator/marketplace-v60-20260713/merge, and verified its exact head 80f809e0b1e8362e99e8f598db21a569a4e0716d before a normal merge. Its first parent is Package/FHC train 0b86a6945439ee1447d77851e86d1b576cbb44dc; 6f38cc1930f7c0f4638355ac6eb9a01e5692802d is an ancestor.
  • Preserved forward migration ownership: Package remains 0033_package_readiness_and_market_batches.sql; the authenticated contact-attempt evidence migration remains 0034_contact_attempt_evidence.sql. The evidence route accepts only idempotent owner-scoped call/text/email events and the refund route derives the sole No response after attempts gate from durable timestamps (12 attempts across at least four days), never client counters/timestamps.
  • The incoming range contains no app/src TS/TSX path and no UI conflict. Documentation was the only conflict surface, resolved additively. Therefore no post-change-polish invocation is appropriate: no touched TSX exists; v60 token fidelity will be proven by parent-tree/source-gate checks without aesthetic drift.
  • Verification: six-screen desktop/mobile component plus refund/contact/security suite passed 18 files / 103 tests; root bun run verify passed 74 files / 660 tests, TypeScript, and Vite assets/index-BLSJB_33.js; FHC passed 457 tests, a fresh 965-page build, and audit; docs built 10 internal + 2 client docs + index. Release-readiness JSON, 0033/0034 order, nine-reason cardinality, public DTO, must-gone, conflict-marker, and staged/working diff checks passed. The staged app/src tree is unchanged from UI first parent, so no TSX post-change-polish invocation was required. Expected forced rollback/compensation test stderr, jsdom window.scrollTo, and Vite's chunk-size advisory remain non-failing diagnostics. No PR, deploy, Stripe action, or Zak message occurred.

2026-07-17 — Exact staging receipt and seed JSON-prefix repair

  • Connected the authorized FHC Chrome profile, verified Cloudflare identity camolechowski@gmail.com, and corrected account token camo-soldi-dns-key with account Workers Scripts Write plus D1 Write while retaining exact Soldi/FHC zone route and DNS authority. Account-token, Workers Scripts, D1, soldi.cc, Workers Routes, and fairhomecash.com provider probes all passed.
  • Deployed exact clean PR #196 head 9de10efd56515af4105e7d9fef2c8aa05bd86354 to protected staging.soldi.cc. The controller minted private receipt deploy-9de10efd56515af4105e7d9fef2c8aa05bd86354.json for deployment 5e97d0c3-5ca8-4acc-a1fc-1c3679809ed5, version 99fe7fd5-61c7-4f7f-8a4d-58d2af2a0175, domain 166ab9a82dc54d854123fb840fc6e3a1ace30de4, migration tip 0036, and test Stripe account acct_1TtjDjPuLV917S5K. Five cache-busted health probes and three Stripe probes matched the exact SHA/version/account after edge propagation.
  • The receipt-bound seed dry-run made no write and stopped on demo_seed_d1_json_invalid. Direct read-only reproduction showed Wrangler --json now writes the exact prefix ├ Checking if file needs uploading\n│\n before a valid JSON envelope. The parser now strips only that exact normalized prefix and continues rejecting arbitrary leading output.
  • Verification: focused staging seed 13 tests / 60 expectations; root bun run verify 79 files / 725 tests, TypeScript, and Vite index-DLsEdVY6.js; git diff --check passed. This source repair changes the candidate SHA, so a new exact-head deployment receipt, seed dry-run/apply/readback, hosted browser QA, retained-production rehearsal, and production promotion remain pending.

2026-07-17 — Transactional protected-staging seed closure

  • Wrangler file mode was proven unsuitable for the guarded transaction: it returns upload statistics instead of SELECT rows and rejects explicit BEGIN IMMEDIATE on remote D1. The controller now reserves Wrangler for exact readback and sends apply/cleanup through Cloudflare's fixed account/database D1 batch endpoint. A hostile live staging batch inserted a unique sentinel and then failed; provider failure plus zero-sentinel readback proved rollback.
  • Exact clean eaf68cc7fab6dbf9d8eed1d26dd32e23fd66334e deployed to staging.soldi.cc as deployment 8724fb36-79ec-411d-91b9-d2144ce1c394, version 38c3cf05-a472-453e-be2b-36294969ae1e, with receipt deploy-eaf68cc7fab6dbf9d8eed1d26dd32e23fd66334e.json. Time Travel bookmark 00000028-00000000-000050ab-075a56a3f89deb2873308b04a3108e80 preceded mutation.
  • The receipt-bound apply created exactly nine marked leads (3 Cold / 3 Warm / 3 Hot) and three ranked Territories for 12 available total. Wallet transactions remained 9, Market purchases 4, refund requests 5, refund outcomes 1, and portfolios 13. There were zero collisions, legacy situations, fixture economic references, or unmarked demo Territories. The next receipt-bound dry-run returned already_seeded.
  • Verification: focused staging seed 17 tests / 81 expectations; root bun run verify 79 files / 725 tests, TypeScript, and Vite index-DLsEdVY6.js; git diff --check passed. Next: redeploy the documentation receipt head, prove served SHA plus seed idempotence, then run hosted desktop/mobile/Stripe acceptance and independent Terra/high review. Production remains held.

2026-07-17 — Hosted Stripe proof and Territory-rank correction

  • Documentation head 4ea90eb38a831d346ba4dc4a8cb5d1f8ba37e3de deployed to protected staging as deployment a82b9f28-1c29-46cb-8668-e6c9b4e34563 / version 1412ed64-bea4-4fb0-a76b-61babf71895a. Three health reads, Stripe identity, and receipt-bound already_seeded readback matched the exact served head.
  • The connected FHC Chrome session completed a real $1,000 Stripe sandbox Checkout with the standard success card. Stripe returned to canonical staging; webhook processing raised demo wallet balance from $5,510 to $6,510; Transactions shows the new typed Stripe funding row and exact running balance.
  • Hosted desktop inspection covered Open Market, My Leads, Transactions, Territories, Payment & Budget, and Settings. All six had exact headings, no horizontal overflow, and none of the checklist's leaderboard/gamer/Comps/Sequences/legacy-taxonomy vocabulary. The pass caught one real blocker: Territory rows hardcoded Position unavailable even though the list API computes rank; mutation responses also dropped rank after create/update.
  • The bounded correction renders Position #N from the server rank, preserves the unavailable fallback for null/paused rows, factors one ranked SQL projection across list/create/update, and proves bid updates return the recalculated position rather than internal priority. The buyer copy delta is exactly Position unavailablePosition #N when rank exists and must be disclosed to Zak. Focused UI/real-SQLite proof passed 2 files / 14 tests; root verification passed 79 files / 726 tests, TypeScript, and Vite index-CrvajqBf.js. Exact-head deploy, mobile rerun, and final rereview remain next; production stays held.
  • Exact correction head e97cfd34a6a42103fa68c6bee7317c1f634ab7a8 then deployed as b09fec39-9da9-41da-a7c1-add9109db7fe / c59aad85-f18d-443e-9b3b-8e39b5869099. Its receipt-bound readback returned already_seeded, positions 1,2,3, 12 available, and wallet count 10 reflecting only the just-proven Stripe funding; Market purchases 4, refund requests 5, refund outcomes 1, and portfolios 13 remained unchanged.
  • Connected FHC Chrome desktop verified visible Position #1/#2/#3, 1728/1728 width, and no application console errors. Chrome DevTools emulation then checked all six routes at exact 390x844: each had the correct H1, 390/390 document width, no leaderboard/gamer/Comps/Sequences/legacy-taxonomy copy, no console errors, and no request status >=400. A physical iPhone and independent exact-head rereview remain open; production stays held.

2026-07-18 — Zak buyer-app iteration (source-only stacked review)

  • Started from exact PR #253 head 2ebc53a096ef9055c1a392900fe7df71f1f42b05 in isolated branch codex/zak-buyer-ui-iteration; no accepted release receipt or deployed runtime was edited in place.
  • Implemented Zak's written 7/18 contract: tier-only Market/My Leads filtering, truthful Package gating, expanded owned-lead dossier and real Offer Out mutation, six-question buyer setup, county-only server-enforced Territories, complete Settings profile/gates, and a non-fabricated $250/$250 referral popup.
  • Preserved Cold $90, Warm $150, Hot $250, Package $5,000/25 Hot leads, wallet/Stripe behavior, and the 12-migration inventory. No provider, D1, Stripe, staging, or production mutation occurred.
  • Mandatory Terra/high UI polish passed 8 files / 74 tests; the retained-Territory follow-up polish passed 2 UI files / 13 tests plus TypeScript and removed a stored legacy-name leak. Final root bun run verify passed 81 files / 736 tests, TypeScript, the production Vite build, brand audit, and 11 production-control tests / 46 assertions. Expected forced-failure diagnostics and jsdom's existing window.scrollTo warning remained non-failing.
  • Copy delta is recorded at /tmp/soldi-zak-ui-copy-delta.md. The promised clickable prototype has not arrived. This UI change deliberately requires fresh migration-rehearsal, Time Travel rollback, protected-staging, hosted, and physical-iPhone receipts before any production-go request.
  • Follow-up read-only production D1 aggregates resolved the retained-Territory question: 4 total/active, 4 situation-filtered, 3 exact-county, 1 no-county, 2 with other hidden constraints, 1 affected buyer; both responses reported changed_db: false, 0 writes. The PR now labels those rows as limited prior scope, disables bid/cap changes, preserves filter bytes, excludes them from county-wide competition, and rejects malformed filters from allocation. No migration or retained-data write occurred; any later cleanup remains a separate reviewed operator action.

2026-07-19 — PR #254 Package profile-routing P1 repair (commit 496976a, source-only)

  • Corrected the 2026-07-18 preservation claim: at exact reviewed head 82da27976c91e21c04cec1ad30868a841aa2de58, the valid client/schema default NJ/NY/TX/FL/IL was not Package-eligible because reservation/completion admitted only one to four markets and had no Illinois canonical mapping. Numeric $5,000 / 25-Hot-lead constants were unchanged, but delivery behavior was not preserved, so the head correctly remained HOLD.
  • The bounded working-tree repair defines NJ/NY/TX/FL/IL once in app/shared/buyer-profile.ts; the client default, Worker Zod schema, Package admission cardinality/allowlist, and canonical lowercase matching consume that authority. No price, quota, reserve policy, wallet/Stripe path, migration, retained Territory, FHC, legal copy, or unrelated UI changed.
  • Real-SQLite proof now drives both an Illinois-only profile and the exact five-market default through a persisted Package reservation, completed fulfillment claim, single delivery, terminal package_completed decision, and zero Market fallback. Malformed JSON, unsupported markets, duplicate markets, and the prior invalid play/volume/budget cases remain fail closed.
  • Verification: focused Package routing/recovery passed 2 files / 42 tests; full app Vitest passed 81 files / 740 tests; standalone bun run typecheck passed; production bun run build passed with index-DK46W7Zq.js. Final root verification and diff hygiene are recorded in the implementation note and /tmp/soldi-pr254-package-routing-fix-receipt.md. Root reviewed and committed the bounded repair as 496976a; no deploy or remote service/data access occurred, and fresh exact-head review remains required after the documentation follow-up lands.

2026-07-19 — Final production-evidence P2 remediation (source-only)

  • Reversed the independent Terra review's four P2 findings in tools/production/** and tools/staging/**: every persisted/input promotion receipt now has a closed exact-key shape and recursive secret-material guard; schema-4 rehearsal (including export), schema-2 rollback, schema-3 staging, Stripe, hosted QA, physical iPhone, and external acceptance fail before a snapshot/executor on extra or bearer/API-key/private-key/Stripe-secret/webhook-secret-shaped content.
  • Hosted desktop proof is now exactly 1440x900; 1280x720 is an explicit hostile rejection. Physical iPhone proof is constrained to the documented approved iPhone/iOS tuple, complete six-step checklist, and digest-bound device-session://soldi-v60/... locator. External acceptance is schema 3 and verifies a fixed-key detached Ed25519 signature over canonical acceptance bytes with a fixed key ID and immutable locator scheme; the new local-only payload command gives the real operator exact signing bytes without storing private key material.
  • Focused proof passed bun run test:production-control (14 tests / 93 assertions, including the real local acceptance-payload CLI path) and bun run test:staging (39 tests / 145 assertions). This source correction does not mint a real rehearsal, staging, Stripe, device, external-signature, or provider receipt. Production remains HOLD pending a future normal-merge candidate and all real V3 gates.

2026-07-19 — Production-evidence P2 rereview reversal (source-only)

  • Reversed the three remaining Terra P2 findings without touching app/src or app/worker: physical-iPhone evidence now contains a closed canonical deviceSessionArtifact; its SHA-256 must equal the receipt field and appear in device-session://soldi-v60/sha256/<digest>, with artifact/tester/device/iOS/checklist mismatches rejected before snapshot or executor work. This is inspectable operator evidence content, explicitly not device-provider attestation.
  • Detached external signatures now require canonical unpadded base64url exactly, 64 decoded Ed25519 bytes, and encode round-trip before fixed-key verification. Hostile padded, whitespace, standard-base64, and junk signatures fail before production calls.
  • acceptance-payload now reads Git source state only for actions that require it. Its focused CLI test runs from a copied archive root with no .git; the real post-commit archive proof remains required before release handoff.
  • Local verification passed production controls 14 tests / 116 assertions, staging controls 39 tests / 145 assertions, full app 81 files / 740 tests plus TypeScript/Vite/brand audit, docs 10 internal + 2 client docs + index, JSON parsing, and diff hygiene.

2026-07-19 — PR #255 Linux CI brand-generator correction (source-only)

  • Exact head 09246a5 failed only GitHub Actions run 29685869734 / job 88189904428: the focused favicon fixture restored the approved social cards but omitted the checked-in mark/dot, causing the full generator to invoke macOS-available magick; Ubuntu had no such executable. The social-copy path itself did not require ImageMagick.
  • Removed that stale fallback. Full generation now treats the reviewed soldi-logo-mark.png and soldi-dot.png as required portable authority beside the logo and source social cards. The focused positive test isolates PATH to Node only, so it proves no host image tool is needed; existing missing logo/wide/square source hostile cases remain.
  • Focused favicon proof passed twice (4 tests each); production controls passed 14 tests / 116 assertions, staging controls 39 tests / 145 assertions, full verification 81 files / 740 tests plus TypeScript/Vite/brand audit, docs 10 internal + 2 client docs + index, JSON parsing, and diff hygiene. Docker has no local Linux Bun image, so the intentionally Node-only PATH test is the executed Linux-compatible reproduction.
  • No supplied transparent logo/favicon, approved Open Graph bytes, metadata, public copy, or application/worker source changed. This fixes CI determinism only; production remains HOLD.

2026-07-19 — PR #255 CI-correction documentation P3 close (docs-only)

  • The CI portability correction is already committed locally as exact 02d9ba6e8575975d018d647c91df8adc1d29b0fb and its hostile rereview is READY. The preceding implementation-note future-tense “commit next” instruction is historical/stale; the actual next step is to push this exact head and obtain green GitHub Linux CI. This docs-only clarification changes no source, asset, provider state, or production gate; production remains HOLD.

2026-07-19 — PR #255 CI documentation handoff correction (docs-only)

  • The preceding docs-only commit advanced the branch, so reviewed CI-fix 02d9ba6 is a parent rather than the push target. Push the resulting current exact branch head after this docs-only commit and obtain green GitHub Linux CI. No source, asset, provider state, or production gate changed; production remains HOLD.
  • Source controls remain reviewable only. No production, staging, provider, device, signature-provider, GitHub, deploy, or message action occurred. Production remains HOLD.

2026-07-19 — PR #255 production-control CI clock correction (source-only)

  • GitHub Actions rerun 29686311048 / job 88191061211 at exact 783ed04864161f919beab51acc668f478d0f4e9f passed app/scripts/favicon-assets.test.mjs on Ubuntu, confirming the prior portability correction. The later root production-control phase alone failed 10/14 tests with production_rehearsal_receipt_stale_or_invalid at promotion.mjs fresh().
  • The test fixture validated against fixed 2026-07-19T12:00:00.000Z but generated rehearsal cleanup/rollback timestamps from the runner wall clock. Once CI reached the phase more than the permitted one-minute future skew later, strict freshness correctly rejected those self-inconsistent fixtures.
  • runProductionRehearsalForTest now permits an explicit fixture clock while defaulting to the existing real wall clock; production execution and its 24-hour freshness policy are unchanged. The fixture pins producer/validator time, asserts both generated timestamps, accepts exactly 24 hours old evidence, and rejects a hostile 24-hours-plus-one-millisecond receipt.
  • This is a local source/test correction only. No brand source/deploy bytes, public copy, app/worker behavior, provider, staging, or production state changed. Production remains HOLD pending the unchanged real final-merge-SHA receipts and V3 authorization.

2026-07-19 — Staging migration receipt controller (source-only)

  • Closed the reviewed-controller direct-Wrangler staging-migration gap with bun run staging:migrate, fixed solely to account 2fb55b3d56fa4a0cb926515ecd0b1a6f and D1 soldi-staging / 516586fe-4d84-4f41-a27a-96bf9d0697c2. It requires a clean freshly fetched two-parent origin/main merge, strict fixed account/zone/domain/D1 read-only authority before snapshot/config/Wrangler work, one private frozen snapshot/toolchain hash, a fresh Time Travel bookmark, strict complete remote migration inventory, retained-data scalars, pending-only apply, and complete post readback.
  • The private 0600 closed-schema receipt is secret-free and binds SHA/tree/parents/canonical config/toolchain/migration hashes and tip/fixed target/bookmark and response hashes/pre-post state/applied set/nonce/cleanup. It records no-op current inventory too. It never restores automatically after a failure; the recorded bookmark is only an incident boundary, not rollback authorization.
  • bun run staging:deploy -- <private-migration-receipt-path> now securely validates the matching fresh receipt before any authority fetch or deploy executor, creates an exact frozen snapshot solely to bind the Wrangler binary, and rechecks receipt tree against the upload snapshot. Source tests cover wrong target/account, malformed envelopes, unknown/gapped/duplicate inventory, stale/substituted/secret-shaped receipts, symlink fences, retained-data loss, no-op, pending order, failure after bookmark, and no-deploy-before-validation.
  • Evidence: bun run test:staging 51 tests / 200 assertions; bun run test:production-control 15 / 120; root bun run verify 81 files / 740 tests with TypeScript/Vite/brand audit; docs build 10 internal + 2 client docs + index; source-only bun run staging:dry-run; and git diff --check passed. Baseline frozen install initially hit Bun sandbox temp AccessDenied, but later Bun test/build commands completed. No provider, D1, bookmark, migration, deploy, credentials, push, PR, or hosted action ran. Public copy delta: NONE. Production remains HOLD.

2026-07-19 — Staging migration controller hostile closure (source-only)

  • Replaced shallow receipt validation with schema-2 closed nesting for inventories, retained scalar names/values, response hashes, migration files, and explicit plannedPending / appliedThisRun / postPending semantics. Exact receipt parents now come from the candidate's two-parent Git row; deployment recomputes the receipt-bound frozen Wrangler SHA-256 before any Cloudflare request or upload.
  • After a valid Time Travel bookmark, the controller writes a private O_EXCL/0600 boundary outside its disposable snapshot before the first later provider command. Provider failure during pre-inventory, apply, post-inventory, or post-retained-data persists a separate secret-free failure receipt with boundary digest, safe phase/error-code classification, and restoreAuthorized:false; no restore is attempted. The success receipt binds the same boundary.
  • Source proof passed bun run test:staging 51 tests / 200 assertions, bun run test:production-control 15 / 120, root bun run verify 81 files / 740 tests, bun run build:docs 10 internal + 2 client docs + index, and git diff --check. The hostile self-review found no upload bypass, stale-evidence, provider-partial-failure, private-file/symlink, or wrong-target P0/P1/P2. No provider, credential, bookmark, migration, deployment, push, PR, or hosted action occurred; public copy delta remains NONE.