AEROSIM-TS-81
Present and execute only valid invalid-state actions
Each invalid-state outcome clearly presents only its permitted recovery, retry, or exit actions and executes the selected action through the flight shell.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-11
- Component
- Web flight shell — invalid-state outcome presenter and action coordinator
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Render InvalidFlightOutcome through InvalidFlightOutcomeViewModel and process OutcomeActionCommand with an exactly-once outcome coordinator. RECOVER delegates to EP3-FT2-03 only when permitted, RETRY creates a new session from the original immutable FlightLaunchRequest with a new sessionId, and EXIT destroys the active flight session and returns route '/'. Freeze simulation input while an outcome is terminal.
Implementation contract
Implementation artifacts
- applications/web/src/flight/outcome/invalid-flight-outcome-panel.tsx
- applications/web/src/flight/outcome/execute-outcome-action.ts
- applications/web/test/flight/invalid-flight-actions.browser.spec.ts
Inputs
- InvalidFlightOutcome and OutcomeActionCommand {commandId,outcomeId,action:'RECOVER'|'RETRY'|'EXIT'}; original FlightLaunchRequest is retained only for RETRY.
Outputs
- OutcomeActionResult {commandId,outcomeId,status:'COMPLETED'|'REJECTED'|'FAILED',action,newSessionId|null,route,recoveryDecision|null,errorCode|null} and a view model containing outcome kind/reason and only allowed action controls.
Failure boundaries
- Reject with ACTION_NOT_ALLOWED when command.action is not in outcome.allowedActions; do not invoke recovery, session creation, or navigation.
- Reject with OUTCOME_STALE when outcomeId is not the active terminal outcome or its sessionId no longer owns the shell.
- A repeated commandId with identical bytes returns the stored result; conflicting bytes return ACTION_COMMAND_CONFLICT and perform no second effect.
- On RECOVER/RETRY setup failure return ACTION_EXECUTION_FAILED, retain the terminal panel, and expose only the still-valid RETRY/EXIT actions; EXIT failure returns EXIT_CLEANUP_FAILED and does not claim route change.
Excluded scope
- Automatic retry, hidden countdown, mid-session configuration changes, account navigation, persistence of outcome history, and adding actions not supplied by the classifier are excluded.
Verification steps
- Run applications/web/test/flight/invalid-flight-actions.browser.spec.ts.
- For CRASHED, OUT_OF_BOUNDS, and UNRECOVERABLE outcomes assert the rendered reason and exact action set, frozen flight input, and no absent action handler.
- Execute permitted RECOVER, RETRY, and EXIT commands; assert restore delegation, new sessionId with original launch config, and completed cleanup before route '/'.
- Execute disallowed, stale, duplicate, conflicting, and injected-failure commands; assert exact result, no duplicate side effect, and truthful terminal state.
Traceability
Acceptance evidence
Verified delivery: application PR #129 merged after exact-head review. InvalidFlightOutcomePanel renders the governed reason and exactly the classifier-supplied actions with terminal input marked frozen. The exactly-once coordinator delegates permitted RECOVER, creates a new-session RETRY from an immutable launch snapshot, and completes EXIT cleanup before route /. It rejects disallowed, stale, duplicate-conflicting, and failed commands without duplicate effects; failed recover/retry retains only RETRY/EXIT. Focused tests pass 11/11, web tests pass 1,066/1,066 plus focused 11/11 and environment presentation 27/27, typecheck, lint, security, build, formatting, and production audit pass; exact-head CI tasks 3658-3667 and integration tasks 3668-3671 passed. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.