feat: atomically journal and deliver authorized native operation outcomes
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
3c5cbfbafe
commit
f0eff0ac92
13 changed files with 583 additions and 28 deletions
|
|
@ -46,8 +46,9 @@ at three seconds, uses TLS, and never follows redirects.
|
|||
Allow is blocked until the archive accepts the authorization record. A lost
|
||||
receipt blocks the business operation even if the attempt reached storage. This
|
||||
is a pre-execution authorization journal, not proof that an operation committed.
|
||||
There is no local success buffer or silent redaction. Domain transaction/outcome
|
||||
atomicity and failure detection remain separate T03/T04 acceptance gates.
|
||||
Authorization cannot use a local success buffer or silent redaction. Native
|
||||
transaction outcomes now use a separate [durable outbox](operation-outcome-audit.md);
|
||||
its production delivery and broader mutation coverage remain T03/T04 gates.
|
||||
|
||||
The exact verified signed decision is retained under `data.signed_decision` as
|
||||
serialized JSON so another serialization of the archive cannot reorder its Go
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue