AEROSIM-TS-19
Implement the pilot-scoped Prisma transaction adapter
The API can perform one governed transactional write and read while enforcing authenticated pilot ownership.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-43
- Component
- API Service — Prisma data adapter
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Implement PilotRecordRepository.createAndReadBack in one Prisma transaction and require AuthenticatedSubject.sub on every create and find operation; all queries include ownerSubject so identifiers alone cannot cross the pilot boundary. Primary files: applications/api/src/persistence/prisma-client.ts, applications/api/src/persistence/pilot-record-repository.ts, applications/api/src/services/save-pilot-record.ts, applications/api/tests/integration/pilot-record-repository.test.ts.
Implementation contract
Implementation artifacts
- applications/api/src/persistence/prisma-client.ts
- applications/api/src/persistence/pilot-record-repository.ts
- applications/api/src/services/save-pilot-record.ts
- applications/api/tests/integration/pilot-record-repository.test.ts
Inputs
- AuthenticatedSubject {sub:string} supplied by the API identity context
- SavePilotRecordCommand {clientRequestId:string,payload:JsonValue}
Outputs
- PilotRecordView {id,clientRequestId,payload,createdAt} scoped to the authenticated subject
- DuplicateRequest result for reuse of (ownerSubject,clientRequestId)
Failure boundaries
- Roll back the insert when read-back or payload validation fails; no partial PilotRecord remains.
- Return NotFound for a record ID owned by another subject and do not reveal that the ID exists.
Excluded scope
- Cross-pilot sharing, administrator queries, record updates, bulk import, and browser-side Prisma access are not supported.
Verification steps
- pnpm --filter @aerosim/api test:integration -- pilot-record-repository.test.ts
- Inject a read-back failure after insert; query PilotRecord directly and assert the transaction persisted zero rows.
Traceability
Dependencies
- AEROSIM-TS-18Canonical ID: TASK-0018
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #34 reviewed head 95330e0fef0305ffc726e87d4d33ccb6b08c043d, exact-head validation task 1865 succeeded, merged as c983d6c943f5cde96986d59e4b116aac7ab83556; Wave 6 integrated application head 5e7babdbc9d3749c062995a48da78cc12a43ef1a passed publish task 1879 and validate task 1880. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.