AEROSIM-TS-58
Implement idempotent pilot-profile resolution
The first authorized request creates one linked pilot profile, while concurrent or later requests for the same Keycloak subject return that same profile.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-31
- Component
- API Service — Pilot profile service, Fastify HTTP boundary, and Prisma data adapter
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Implement a transaction-safe find-or-create operation in the Pilot profile service, resolve ownership exclusively from the authenticated subject context, handle uniqueness races idempotently, and expose a typed current-profile endpoint without accepting a caller-supplied subject. Concrete artifacts are prisma/schema.prisma and tests/integration/implement-idempotent-pilot-profile-resolution.spec.ts; ownership is limited to the listed artifacts and their focused verification.
Implementation contract
Implementation artifacts
- prisma/schema.prisma
- prisma/migrations/implement-idempotent-pilot-profile-resolution/migration.sql
- tests/integration/implement-idempotent-pilot-profile-resolution.spec.ts
Inputs
- Validated authenticated-subject context produced by the API identity guard
- Current-profile request with no caller-selected subject
- Pilot profile repository operating inside a database transaction
Outputs
- The first authorized request creates one linked pilot profile, while concurrent or later requests for the same Keycloak subject return that same profile.
Failure boundaries
- Reject subject-free requests and ignore or reject any caller-supplied subject selector
- Resolve uniqueness races by reading the winning profile after conflict; never return two profile identities for one subject
Excluded scope
- Profile lookup by arbitrary subject, email address, or display name
- Profile editing beyond the safe defaults needed to establish the current pilot
Verification steps
- Run tests/integration/implement-idempotent-pilot-profile-resolution.spec.ts against the exact implementation revision and retain the complete passing result.
- Exercise the positive contract with validated authenticated-subject context produced by the api identity guard, then assert: The first authorized request creates one linked pilot profile, while concurrent or later requests for the same Keycloak subject return that same profile.
- Exercise every negative boundary: Reject subject-free requests and ignore or reject any caller-supplied subject selector; Resolve uniqueness races by reading the winning profile after conflict; never return two profile identities for one subject
Traceability
Dependencies
- AEROSIM-TS-57Canonical ID: TASK-0057
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #65 reviewed head 19b8ae57a1193272b40be2be29a361819adff645, exact-head required validation task 2125 succeeded, merged as 15449bdcfccc4b38538f88d9192bb745395bb0ef; current integrated application head 7de1a447a7aa95c20ec69a66c9713e8e4474b895 passed required validation task 2142, publish task 2140, and validate task 2141. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.