diff --git a/TODO_NEXT_STEPS.txt b/TODO_NEXT_STEPS.txt
index 38c848a..3db16c2 100644
--- a/TODO_NEXT_STEPS.txt
+++ b/TODO_NEXT_STEPS.txt
@@ -141,6 +141,8 @@
- Phase 67 candidate queue review decision approval:新增 `services/market_intel/candidate_queue_review_decision_approval.py`、POST `/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval` 與 UI approval gate 按鈕,檢查人工決策草案是否可進入下一個 CLI-only transaction preview;API/UI 不更新 review_state、不寫 decision record、不建立 approval record、不讀 token、不掛 scheduler;版本同步至 V10.255。
- Phase 68 candidate queue review decision transaction:新增 `services/market_intel/candidate_queue_review_decision_transaction.py`、POST `/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction` 與 UI transaction preview 按鈕,將 approval update preview 轉成 `review_state` update statement、payload hash 與 rollback plan;API/UI 不更新 review_state、不開 DB connection、不執行 CLI、不讀 token、不掛 scheduler;版本同步至 V10.256。
- Phase 69 candidate queue review decision writer CLI gate:新增 `services/market_intel/candidate_queue_review_decision_writer_cli.py`、`scripts/market_intel_review_decision_writer.py`、POST `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status` 與 UI writer gate 按鈕,先建立 shell-only review_state writer gate 與 command bundle;writer implementation 本階段保持 disabled,API/UI 不讀 token、不執行 CLI、不連 DB、不更新 review_state、不掛 scheduler;版本同步至 V10.257。
+ - Phase 70 candidate queue review decision writer preflight:新增 `services/market_intel/candidate_queue_review_decision_writer_preflight.py`、POST `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight` 與 UI preflight 按鈕,檢查 writer status、review_state update payload、狀態轉換與禁止 token 進 API;API/UI 即使收到 execute/apply_real_write 也不連 DB、不執行 CLI、不更新 review_state、不 commit、不讀 token、不掛 scheduler;版本同步至 V10.258。
+ - V10.259 補 Phase 70 preflight 合約與 OCLearn queue 時區:preflight 補 planned/read-only catalog probe 欄位、dedupe unique index 檢查與 route 重複註冊清理;OCLearn embedding queue 的 created_at/updated_at/stale cutoff 改為台北 naive,避免 UTC/台北時間差讓 processing 任務卡住。
- V10.248 補市場情報 390px preview panel QA:sample review 工具列改為 textarea + 可換行 action rail,移除舊的硬編 8 欄 grid;`check_responsive_overflow` 新增 `--screenshot-all`,本機 390x844 `/market_intel` 真頁面 QA 通過且 overflow=0。
- V10.250 補 Code Review Gemini 備援遙測護欄:Ollama 主路徑失敗時 `fallback_to` 明確指向 `code_review_openclaw_gemini`,測試鎖住「Gemini 不得記成 `code_review_openclaw` 主 caller」;AI Calls 觀測台會把 legacy `code_review_openclaw + gemini` 顯示成 Gemini 備援,避免誤判 Gemini-first。
- Schema smoke:`tests/test_market_intel_skeleton.py` 檢查 `Base.metadata` 內含 ADR-035 八張 `market_*` tables。
diff --git a/config.py b/config.py
index d7ec5ea..1721600 100644
--- a/config.py
+++ b/config.py
@@ -320,7 +320,7 @@ YOUTUBE_API_KEY = os.getenv('YOUTUBE_API_KEY', '')
# ==========================================
# 系統版本與路徑
# ==========================================
-SYSTEM_VERSION = "V10.257"
+SYSTEM_VERSION = "V10.259"
LOG_FILE_PATH = os.path.join(BASE_DIR, 'logs/system.log')
public_url = PUBLIC_URL # 用於模板顯示
diff --git a/docs/adr/ADR-035-cross-platform-market-campaign-intelligence.md b/docs/adr/ADR-035-cross-platform-market-campaign-intelligence.md
index fde44bb..1104f34 100644
--- a/docs/adr/ADR-035-cross-platform-market-campaign-intelligence.md
+++ b/docs/adr/ADR-035-cross-platform-market-campaign-intelligence.md
@@ -195,6 +195,7 @@ EwoooC 目前已有 MOMO EDM / 節慶活動資料、`promo_products`、PChome
- 2026-05-19 追加 candidate queue review decision approval:`services.market_intel.candidate_queue_review_decision_approval` 與 `/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval` 檢查人工決策草案是否可進入下一個 CLI-only transaction preview。此階段不更新 `review_state`、不寫 decision record、不建立 approval record、不讀 approval token、不掛 scheduler。
- 2026-05-19 追加 candidate queue review decision transaction:`services.market_intel.candidate_queue_review_decision_transaction` 與 `/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction` 將已批准的人工決策整理成 `review_state` update statement preview、payload hash、runtime order 與 rollback plan。此階段不連 DB、不開 transaction、不 commit、不更新 `review_state`、不讀 approval token、不執行 CLI、不掛 scheduler;真正更新只允許後續人工 shell/CLI 寫入窗口。
- 2026-05-19 追加 candidate queue review decision writer CLI gate:`services.market_intel.candidate_queue_review_decision_writer_cli`、`scripts/market_intel_review_decision_writer.py` 與 `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status` 先建立 review_state writer 的 shell-only gate、一次性 token env var、command bundle 與 rollback plan。此階段 writer implementation 保持 disabled;API/UI 不讀 approval token、不執行 CLI、不連 DB、不開 transaction、不 commit、不更新 `review_state`、不掛 scheduler。
+- 2026-05-19 追加 candidate queue review decision writer preflight:`services.market_intel.candidate_queue_review_decision_writer_preflight` 與 `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight` 檢查 writer status、review_state update payload、狀態轉換與 token 外洩風險。API/UI 即使收到 `execute=true` 或 `apply_real_write=true` 也只回 blocked preview,不連 DB、不執行 CLI、不更新 `review_state`、不 commit、不讀 approval token、不掛 scheduler。
### Phase 4:Coupang / Shopee Adapter
diff --git a/routes/README.md b/routes/README.md
index 0185552..3c3a3c1 100644
--- a/routes/README.md
+++ b/routes/README.md
@@ -19,8 +19,8 @@
| `edm_routes.py` | EDM 與節慶儀表板 | `/edm`, `/festival` |
| `monthly_routes.py` | 月結分析 | `/monthly_summary_analysis`, `/api/monthly_summary_data` |
| `daily_sales_routes.py` | 當日業績 | `/daily_sales`, `/daily_sales/export*` |
-| `market_intel_routes.py` | 市場情報 Phase 69 candidate queue review decision writer CLI gate 主路由 | `/market_intel`, `/market_intel/*`, `/api/market_intel/status`, `/api/market_intel/schema`, `/api/market_intel/schema_smoke`, `/api/market_intel/schema_db_probe`, `/api/market_intel/platform_seed_db_diff`, `/api/market_intel/legacy_source_bridge`, `/api/market_intel/mcp_readiness`, `/api/market_intel/mcp_tool_contract`, `/api/market_intel/mcp_deploy_preflight`, `/api/market_intel/mcp_activation_runbook`, `/api/market_intel/mcp_fetch_gate`, `/api/market_intel/scheduler_plan`, `/api/market_intel/manual_sample_plan`, `/api/market_intel/manual_sample_acceptance`, `/api/market_intel/manual_sample_review`, `/api/market_intel/manual_sample_review/evaluate`, `/api/market_intel/manual_sample_review/candidate_handoff`, `/api/market_intel/manual_sample_review/candidate_queue_draft`, `/api/market_intel/manual_sample_review/candidate_queue_approval`, `/api/market_intel/manual_sample_review/candidate_queue_transaction`, `/api/market_intel/manual_sample_review/candidate_queue_writer_status`, `/api/market_intel/manual_sample_review/candidate_queue_writer_preflight`, `/api/market_intel/manual_sample_review/candidate_queue_writer_postwrite_smoke`, `/api/market_intel/manual_sample_review/candidate_queue_writer_operator_drill`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_package`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_readiness`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_receipt`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_closeout`, `/api/market_intel/manual_sample_review/candidate_queue_review_handoff`, `/api/market_intel/match_review_plan`, `/api/market_intel/opportunity_plan`, `/api/market_intel/opportunity_scoring_plan`, `/api/market_intel/opportunity_evidence_plan`, `/api/market_intel/opportunity_alert_plan`, `/api/market_intel/adapters`, `/api/market_intel/dry_run_plan`, `/api/market_intel/discovery_plan`, `/api/market_intel/manual_discovery`, `/api/market_intel/candidate_preview`, `/api/market_intel/platform_seed_plan`, `/api/market_intel/platform_seed_write_guard`, `/api/market_intel/platform_seed_writer_plan`, `/api/market_intel/migration_blueprint`, `/api/market_intel/migration_apply_drill`, `/api/market_intel/migration_catalog_review`, `/api/market_intel/migration_live_smoke`, `/api/market_intel/live_db_inventory`, `/api/market_intel/seed_writer_cli_status`, `/api/market_intel/write_approval_runbook`, `/api/market_intel/deployment_readiness` |
-| `market_intel_review_routes.py` | 市場情報人工 queue review 只讀延伸 API | `/api/market_intel/manual_sample_review/candidate_queue_review_inventory`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status` |
+| `market_intel_routes.py` | 市場情報 Phase 70 candidate queue review decision writer preflight 主路由 | `/market_intel`, `/market_intel/*`, `/api/market_intel/status`, `/api/market_intel/schema`, `/api/market_intel/schema_smoke`, `/api/market_intel/schema_db_probe`, `/api/market_intel/platform_seed_db_diff`, `/api/market_intel/legacy_source_bridge`, `/api/market_intel/mcp_readiness`, `/api/market_intel/mcp_tool_contract`, `/api/market_intel/mcp_deploy_preflight`, `/api/market_intel/mcp_activation_runbook`, `/api/market_intel/mcp_fetch_gate`, `/api/market_intel/scheduler_plan`, `/api/market_intel/manual_sample_plan`, `/api/market_intel/manual_sample_acceptance`, `/api/market_intel/manual_sample_review`, `/api/market_intel/manual_sample_review/evaluate`, `/api/market_intel/manual_sample_review/candidate_handoff`, `/api/market_intel/manual_sample_review/candidate_queue_draft`, `/api/market_intel/manual_sample_review/candidate_queue_approval`, `/api/market_intel/manual_sample_review/candidate_queue_transaction`, `/api/market_intel/manual_sample_review/candidate_queue_writer_status`, `/api/market_intel/manual_sample_review/candidate_queue_writer_preflight`, `/api/market_intel/manual_sample_review/candidate_queue_writer_postwrite_smoke`, `/api/market_intel/manual_sample_review/candidate_queue_writer_operator_drill`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_package`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_readiness`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_receipt`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_closeout`, `/api/market_intel/manual_sample_review/candidate_queue_review_handoff`, `/api/market_intel/match_review_plan`, `/api/market_intel/opportunity_plan`, `/api/market_intel/opportunity_scoring_plan`, `/api/market_intel/opportunity_evidence_plan`, `/api/market_intel/opportunity_alert_plan`, `/api/market_intel/adapters`, `/api/market_intel/dry_run_plan`, `/api/market_intel/discovery_plan`, `/api/market_intel/manual_discovery`, `/api/market_intel/candidate_preview`, `/api/market_intel/platform_seed_plan`, `/api/market_intel/platform_seed_write_guard`, `/api/market_intel/platform_seed_writer_plan`, `/api/market_intel/migration_blueprint`, `/api/market_intel/migration_apply_drill`, `/api/market_intel/migration_catalog_review`, `/api/market_intel/migration_live_smoke`, `/api/market_intel/live_db_inventory`, `/api/market_intel/seed_writer_cli_status`, `/api/market_intel/write_approval_runbook`, `/api/market_intel/deployment_readiness` |
+| `market_intel_review_routes.py` | 市場情報人工 queue review 只讀延伸 API | `/api/market_intel/manual_sample_review/candidate_queue_review_inventory`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight` |
| `api_routes.py` | 通用任務與查詢 API | `/api/run_task`, `/api/history/*` |
| `export_routes.py` | 匯出功能 | `/api/export/*` |
| `import_routes.py` | 匯入功能 | `/api/import_excel`, `/api/import/monthly_summary` |
diff --git a/routes/market_intel_review_routes.py b/routes/market_intel_review_routes.py
index 725de40..62d447a 100644
--- a/routes/market_intel_review_routes.py
+++ b/routes/market_intel_review_routes.py
@@ -24,6 +24,9 @@ from services.market_intel.candidate_queue_review_decision_transaction import (
from services.market_intel.candidate_queue_review_decision_writer_cli import (
build_candidate_queue_review_decision_writer_cli_plan,
)
+from services.market_intel.candidate_queue_review_decision_writer_preflight import (
+ build_candidate_queue_review_decision_writer_preflight,
+)
from services.market_intel.candidate_queue_writer_cli import (
build_candidate_queue_writer_cli_plan,
)
@@ -383,3 +386,48 @@ def market_intel_manual_sample_candidate_queue_review_decision_writer_status():
)
data["phase"] = service.phase
return jsonify(data), 400 if payload_error else 200
+
+
+@market_intel_review_bp.route(
+ "/api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_preflight",
+ methods=["POST"],
+)
+@login_required
+def market_intel_manual_sample_candidate_queue_review_decision_writer_preflight():
+ service = MarketIntelService()
+ execute_requested = request.args.get("execute", "false").lower() == "true"
+ apply_real_write = (
+ request.args.get("apply_real_write", "false").lower() == "true"
+ )
+ sample_result, operator_evidence, writer_output, smoke_result, payload_error, limit = (
+ _extract_run_payload()
+ )
+ transaction = _build_review_decision_transaction_stack(
+ service=service,
+ sample_result=sample_result,
+ payload_error=payload_error,
+ operator_evidence=operator_evidence,
+ writer_output=writer_output,
+ postwrite_smoke_result=smoke_result,
+ limit=limit,
+ execute_requested=False,
+ )
+ writer_status = build_candidate_queue_review_decision_writer_cli_plan(
+ transaction_preview=transaction,
+ execute_requested=False,
+ apply_real_write=False,
+ approval_token=None,
+ approval_token_secret=None,
+ backup_verified=False,
+ review_inventory_smoke_passed=False,
+ )
+ data = build_candidate_queue_review_decision_writer_preflight(
+ writer_status=writer_status,
+ transaction_preview=transaction,
+ operator_evidence=operator_evidence,
+ execute_requested=execute_requested,
+ apply_real_write=apply_real_write,
+ )
+ data["phase"] = service.phase
+ return jsonify(data), 400 if payload_error else 200
diff --git a/services/market_intel/candidate_queue_review_decision_writer_preflight.py b/services/market_intel/candidate_queue_review_decision_writer_preflight.py
new file mode 100644
index 0000000..87fad3c
--- /dev/null
+++ b/services/market_intel/candidate_queue_review_decision_writer_preflight.py
@@ -0,0 +1,507 @@
+"""候選審核 queue review_state writer preflight。
+
+本模組只檢查 review_state writer status、transaction payload 與 catalog
+欄位合約;不讀 token、不更新 review_state、不 commit、不掛 scheduler。
+"""
+
+from sqlalchemy import inspect
+
+
+TARGET_TABLE = "market_alert_review_queue"
+TARGET_OPERATION = "update_review_state"
+ALLOWED_DECISIONS = ("confirmed", "rejected", "deferred")
+FORBIDDEN_TOKEN_KEYWORDS = (
+ "approval_token",
+ "approval-token",
+ "market_intel_queue_write_approval",
+)
+SAFE_TOKEN_METADATA_KEYS = {
+ "approval_token_present",
+ "approval_token_valid",
+ "approval_token_secret_configured",
+}
+APPROVAL_ENV_VAR = "MARKET_INTEL_QUEUE_WRITE_APPROVAL"
+PAYLOAD_COLUMN_MAP = {
+ "dedupe_key": "dedupe_key",
+ "next_review_state": "review_state",
+}
+REQUIRED_UPDATE_COLUMNS = [
+ "dedupe_key",
+ "review_state",
+ "reviewed_at",
+ "updated_at",
+]
+BLOCKED_WRITE_FLAGS = (
+ "ready_for_api_database_write",
+ "ready_for_scheduler_attach",
+ "review_state_update_allowed_from_api",
+ "api_executes_cli",
+ "api_reads_approval_token",
+ "api_writes_file",
+ "api_writes_database",
+ "api_updates_review_state",
+ "approval_record_written",
+ "decision_record_written",
+ "review_state_update_executed",
+ "database_connection_opened",
+ "database_session_created",
+ "explicit_transaction_opened",
+ "transaction_opened",
+ "transaction_committed",
+ "database_write_executed",
+ "database_commit_executed",
+ "database_rollback_executed",
+ "scheduler_attached",
+ "writes_executed",
+ "would_write_database",
+)
+
+
+def _as_dict(value):
+ return value if isinstance(value, dict) else {}
+
+
+def _as_list(value):
+ if value is None:
+ return []
+ if isinstance(value, (list, tuple, set)):
+ return list(value)
+ return [value]
+
+
+def _contains_forbidden_token_key(value):
+ if isinstance(value, dict):
+ for key, nested in value.items():
+ normalized_key = str(key).lower()
+ if normalized_key in SAFE_TOKEN_METADATA_KEYS and isinstance(nested, bool):
+ continue
+ if normalized_key == "approval_env_var" and nested == APPROVAL_ENV_VAR:
+ continue
+ if any(token_key in normalized_key for token_key in FORBIDDEN_TOKEN_KEYWORDS):
+ return True
+ if _contains_forbidden_token_key(nested):
+ return True
+ elif isinstance(value, list):
+ return any(_contains_forbidden_token_key(item) for item in value)
+ return False
+
+
+def _transaction_statement_payloads(transaction_preview):
+ payloads = []
+ for statement in _as_list(_as_dict(transaction_preview).get("statements")):
+ statement = _as_dict(statement)
+ parameter_preview = _as_dict(statement.get("parameter_preview"))
+ lookup = _as_dict(statement.get("lookup"))
+ dedupe_key = (
+ parameter_preview.get("dedupe_key")
+ or lookup.get("dedupe_key")
+ or statement.get("dedupe_key")
+ )
+ current_state = (
+ parameter_preview.get("expected_current_review_state")
+ or statement.get("expected_current_review_state")
+ )
+ next_state = (
+ parameter_preview.get("next_review_state")
+ or statement.get("next_review_state")
+ )
+ payloads.append(
+ {
+ "idempotency_key": statement.get("idempotency_key"),
+ "dedupe_key": dedupe_key,
+ "expected_current_review_state": current_state,
+ "next_review_state": next_state,
+ "statement_type": statement.get("statement_type")
+ or "update_review_state",
+ "operation": statement.get("operation") or "update",
+ "parameter_payload_hash": statement.get("parameter_payload_hash"),
+ "write_status": "blocked_preflight_only",
+ }
+ )
+ return payloads
+
+
+def _statement_payloads(writer_status, transaction_preview):
+ writer_status = _as_dict(writer_status)
+ payloads = _as_list(writer_status.get("statement_payloads"))
+ if payloads:
+ return [_as_dict(item) for item in payloads]
+
+ payloads = (
+ _as_dict(writer_status)
+ .get("statement_summary", {})
+ .get("review_state_updates", [])
+ )
+ if payloads:
+ return [_as_dict(item) for item in _as_list(payloads)]
+
+ return _transaction_statement_payloads(transaction_preview)
+
+
+def _validate_payloads(payloads):
+ invalid = []
+ normalized = []
+ for payload in payloads:
+ payload = _as_dict(payload)
+ dedupe_key = payload.get("dedupe_key")
+ current_state = payload.get("expected_current_review_state")
+ next_state = payload.get("next_review_state")
+ row = {
+ "idempotency_key": payload.get("idempotency_key"),
+ "dedupe_key": dedupe_key,
+ "expected_current_review_state": current_state,
+ "next_review_state": next_state,
+ "statement_type": payload.get("statement_type") or "update_review_state",
+ "operation": payload.get("operation") or "update",
+ "parameter_payload_hash": payload.get("parameter_payload_hash"),
+ "write_status": "blocked_preflight_only",
+ }
+ missing_fields = [
+ key
+ for key in (
+ "dedupe_key",
+ "expected_current_review_state",
+ "next_review_state",
+ )
+ if not row.get(key)
+ ]
+ invalid_transition = bool(
+ current_state != "needs_review" or next_state not in ALLOWED_DECISIONS
+ )
+ invalid_operation = bool(
+ row["operation"] != "update"
+ or row["statement_type"] != "update_review_state"
+ )
+ if missing_fields or invalid_transition or invalid_operation:
+ invalid.append(
+ {
+ "idempotency_key": row["idempotency_key"],
+ "dedupe_key": dedupe_key,
+ "missing_fields": missing_fields,
+ "transition_invalid": invalid_transition,
+ "operation_invalid": invalid_operation,
+ }
+ )
+ normalized.append(row)
+ return normalized, invalid
+
+
+def _writer_status_safe(writer_status):
+ writer_status = _as_dict(writer_status)
+ if not writer_status:
+ return True
+ return bool(
+ writer_status.get("mode")
+ == "candidate_queue_review_decision_writer_cli_blocked"
+ and all(not writer_status.get(key) for key in BLOCKED_WRITE_FLAGS)
+ )
+
+
+def _operator_summary(operator_evidence):
+ operator_evidence = _as_dict(operator_evidence)
+ return {
+ "provided_keys": sorted(operator_evidence.keys()),
+ "approval_token_submitted_to_api": _contains_forbidden_token_key(
+ operator_evidence
+ ),
+ "operator_confirmed_no_api_db_write": bool(
+ operator_evidence.get("operator_confirmed_no_api_db_write")
+ ),
+ "operator_confirmed_no_scheduler_attach": bool(
+ operator_evidence.get("operator_confirmed_no_scheduler_attach")
+ ),
+ "operator_confirmed_review_state_preflight_only": bool(
+ operator_evidence.get("operator_confirmed_review_state_preflight_only")
+ ),
+ }
+
+
+def _planned_catalog_probe(database_type):
+ return {
+ "mode": "planned_only",
+ "database_type": database_type or "unknown",
+ "table_exists": False,
+ "schema_ready": False,
+ "read_only_query_executed": False,
+ "database_connection_opened": False,
+ "columns": [],
+ "missing_update_columns": list(REQUIRED_UPDATE_COLUMNS),
+ "dedupe_unique_index_present": False,
+ "required_columns": list(REQUIRED_UPDATE_COLUMNS),
+ "required_unique_lookup": "dedupe_key",
+ "next_stage": "manual_shell_catalog_probe_before_writer_enable",
+ }
+
+
+def _read_only_catalog_probe(engine, database_type):
+ probe = _planned_catalog_probe(database_type)
+ probe["mode"] = "read_only"
+ probe["read_only_query_executed"] = True
+ try:
+ with engine.connect() as connection:
+ probe["database_connection_opened"] = True
+ inspector = inspect(connection)
+ table_exists = TARGET_TABLE in set(inspector.get_table_names())
+ probe["table_exists"] = table_exists
+ if table_exists:
+ columns = [
+ str(column.get("name"))
+ for column in inspector.get_columns(TARGET_TABLE)
+ ]
+ indexes = inspector.get_indexes(TARGET_TABLE)
+ try:
+ unique_constraints = inspector.get_unique_constraints(
+ TARGET_TABLE
+ )
+ except Exception:
+ unique_constraints = []
+ unique_column_sets = [
+ set(index.get("column_names") or [])
+ for index in indexes
+ if index.get("unique")
+ ]
+ unique_column_sets.extend(
+ set(constraint.get("column_names") or [])
+ for constraint in unique_constraints
+ )
+ probe["columns"] = columns
+ probe["missing_update_columns"] = [
+ column
+ for column in REQUIRED_UPDATE_COLUMNS
+ if column not in columns
+ ]
+ probe["dedupe_unique_index_present"] = any(
+ "dedupe_key" in column_set for column_set in unique_column_sets
+ )
+ probe["schema_ready"] = bool(
+ probe["table_exists"]
+ and not probe["missing_update_columns"]
+ and probe["dedupe_unique_index_present"]
+ )
+ except Exception as exc:
+ probe["error"] = str(exc)[:300]
+ return probe
+
+
+def _safety_contract():
+ return {
+ "target_table": TARGET_TABLE,
+ "target_operation": TARGET_OPERATION,
+ "valid_current_review_state": "needs_review",
+ "allowed_next_states": list(ALLOWED_DECISIONS),
+ "read_only_payload_check_only": True,
+ "does_not_read_approval_token": True,
+ "does_not_update_review_state": True,
+ "does_not_commit_transaction": True,
+ "does_not_attach_scheduler": True,
+ }
+
+
+def build_candidate_queue_review_decision_writer_preflight(
+ *,
+ transaction_preview,
+ writer_status=None,
+ operator_evidence=None,
+ execute_requested=False,
+ apply_real_write=False,
+ engine=None,
+ database_type=None,
+):
+ """建立 review_state writer preflight;不執行 update 或 commit。"""
+ writer_status = _as_dict(writer_status)
+ transaction_preview = _as_dict(transaction_preview)
+ operator_summary = _operator_summary(operator_evidence)
+ statement_payloads, invalid_payloads = _validate_payloads(
+ _statement_payloads(writer_status, transaction_preview)
+ )
+ catalog_probe = (
+ _read_only_catalog_probe(engine, database_type)
+ if execute_requested and engine is not None
+ else _planned_catalog_probe(database_type)
+ )
+ read_only_probe_loaded = bool(catalog_probe["read_only_query_executed"])
+ transaction_summary = writer_status.get("transaction_preview_summary") or {}
+ transaction_ready = bool(
+ transaction_summary.get("transaction_ready")
+ or transaction_preview.get("transaction_ready")
+ )
+ payload_ready = bool(statement_payloads and not invalid_payloads)
+ writer_safe = _writer_status_safe(writer_status)
+ writer_implementation_enabled = bool(
+ writer_status.get("writer_implementation_enabled")
+ )
+ schema_ready = bool(catalog_probe["schema_ready"])
+ ready_for_writer_review = bool(
+ read_only_probe_loaded
+ and schema_ready
+ and transaction_ready
+ and payload_ready
+ and writer_safe
+ and not operator_summary["approval_token_submitted_to_api"]
+ and not apply_real_write
+ )
+ mode = (
+ "candidate_queue_review_decision_writer_preflight_read_only"
+ if read_only_probe_loaded
+ else "candidate_queue_review_decision_writer_preflight_preview"
+ )
+ gates = [
+ {
+ "key": "writer_status_is_blocked_cli_gate",
+ "label": "上一階段 writer status 必須停在 blocked CLI gate 或未載入",
+ "passed": writer_safe,
+ },
+ {
+ "key": "transaction_preview_ready",
+ "label": "review_state transaction preview 必須已通過人工 gate",
+ "passed": transaction_ready,
+ },
+ {
+ "key": "statement_payloads_present",
+ "label": "preflight 必須收到 update_review_state statement payload",
+ "passed": bool(statement_payloads),
+ },
+ {
+ "key": "statement_payloads_valid",
+ "label": "statement payload 必須符合 needs_review 轉人工決策狀態",
+ "passed": payload_ready,
+ },
+ {
+ "key": "preflight_no_token_submitted_to_api",
+ "label": "operator_evidence 不得包含一次性 approval token key",
+ "passed": not operator_summary["approval_token_submitted_to_api"],
+ },
+ {
+ "key": "preflight_execute_not_requested_from_api",
+ "label": "API preflight 不執行任何 shell/DB 動作",
+ "passed": not execute_requested,
+ },
+ {
+ "key": "preflight_apply_real_write_not_requested_from_api",
+ "label": "API preflight 不接受 apply_real_write",
+ "passed": not apply_real_write,
+ },
+ {
+ "key": "review_decision_writer_preflight_read_only_probe_loaded",
+ "label": "正式 writer 前需人工觸發只讀 catalog probe",
+ "passed": read_only_probe_loaded,
+ },
+ {
+ "key": "review_decision_writer_preflight_schema_ready",
+ "label": "catalog 必須具備 review_state update 必要欄位與 dedupe unique index",
+ "passed": schema_ready,
+ },
+ {
+ "key": "review_decision_writer_implementation_enabled",
+ "label": "review_state writer 實作尚未啟用,本階段只做 preflight",
+ "passed": writer_implementation_enabled,
+ },
+ ]
+ blocked_reasons = [gate["key"] for gate in gates if not gate["passed"]]
+ if not read_only_probe_loaded:
+ blocked_reasons.append("review_decision_writer_preflight_not_loaded")
+ if ready_for_writer_review:
+ blocked_reasons = []
+
+ return {
+ "mode": mode,
+ "target_table": TARGET_TABLE,
+ "target_operation": TARGET_OPERATION,
+ "execute_requested": bool(execute_requested),
+ "apply_real_write_requested": bool(apply_real_write),
+ "preflight_payload_ready": payload_ready,
+ "writer_status_safe": writer_safe,
+ "writer_implementation_enabled": writer_implementation_enabled,
+ "preflight_ready": ready_for_writer_review,
+ "ready_for_writer_review": ready_for_writer_review,
+ "ready_for_review_state_writer_review": ready_for_writer_review,
+ "ready_for_real_write": False,
+ "ready_for_api_review_state_update": False,
+ "ready_for_api_database_write": False,
+ "ready_for_scheduler_attach": False,
+ "review_state_update_allowed_from_api": False,
+ "api_executes_cli": False,
+ "api_reads_approval_token": False,
+ "api_writes_file": False,
+ "api_writes_database": False,
+ "api_updates_review_state": False,
+ "approval_record_written": False,
+ "decision_record_written": False,
+ "review_state_update_executed": False,
+ "read_only_query_executed": bool(catalog_probe["read_only_query_executed"]),
+ "database_connection_opened": bool(
+ catalog_probe["database_connection_opened"]
+ ),
+ "database_session_created": False,
+ "explicit_transaction_opened": False,
+ "transaction_opened": False,
+ "transaction_committed": False,
+ "database_write_executed": False,
+ "database_commit_executed": False,
+ "database_rollback_executed": False,
+ "external_network_executed": False,
+ "scheduler_attached": False,
+ "writes_executed": False,
+ "would_write_database": False,
+ "statement_count": len(statement_payloads),
+ "invalid_statement_count": len(invalid_payloads),
+ "invalid_statements": invalid_payloads,
+ "payload_column_map": dict(PAYLOAD_COLUMN_MAP),
+ "mapped_update_columns": list(PAYLOAD_COLUMN_MAP.values()),
+ "required_update_columns": list(REQUIRED_UPDATE_COLUMNS),
+ "unmapped_payload_keys": [],
+ "table_exists": bool(catalog_probe["table_exists"]),
+ "schema_ready": schema_ready,
+ "missing_update_columns": list(catalog_probe["missing_update_columns"]),
+ "dedupe_unique_index_present": bool(
+ catalog_probe["dedupe_unique_index_present"]
+ ),
+ "blocked_reasons": blocked_reasons,
+ "preflight_gates": gates,
+ "operator_preflight_summary": operator_summary,
+ "statement_summary": {
+ "statement_count": len(statement_payloads),
+ "invalid_statement_count": len(invalid_payloads),
+ "invalid_statements": invalid_payloads,
+ "allowed_next_states": list(ALLOWED_DECISIONS),
+ "review_state_updates": statement_payloads,
+ },
+ "transaction_preview_summary": {
+ "mode": transaction_summary.get("mode") or transaction_preview.get("mode"),
+ "transaction_ready": transaction_ready,
+ "statement_count": (
+ transaction_summary.get("statement_count")
+ or len(_as_list(transaction_preview.get("statements")))
+ ),
+ "api_write_allowed": False,
+ },
+ "update_contract": {
+ "target_table": TARGET_TABLE,
+ "operation": "update",
+ "statement_type": "update_review_state",
+ "lookup": "dedupe_key",
+ "expected_current_review_state": "needs_review",
+ "allowed_next_states": list(ALLOWED_DECISIONS),
+ "payload_column_map": dict(PAYLOAD_COLUMN_MAP),
+ "required_update_columns": list(REQUIRED_UPDATE_COLUMNS),
+ "required_payload_fields": [
+ "dedupe_key",
+ "expected_current_review_state",
+ "next_review_state",
+ ],
+ },
+ "catalog_probe_plan": catalog_probe,
+ "safety_contract": _safety_contract(),
+ "safe_boundaries": [
+ "do_not_execute_review_state_preflight_from_api",
+ "do_not_execute_review_decision_writer_from_preflight_api",
+ "do_not_read_approval_token_from_review_state_preflight_api",
+ "do_not_open_database_connection_from_review_state_writer_preflight",
+ "do_not_commit_review_state_writer_preflight",
+ "do_not_update_review_state_from_review_state_preflight",
+ "do_not_update_review_state_from_review_state_writer_preflight",
+ "do_not_attach_scheduler_from_review_state_writer_preflight",
+ "no_remove_orphans",
+ "no_momo_db_lifecycle_change",
+ ],
+ }
diff --git a/services/market_intel/deployment_readiness.py b/services/market_intel/deployment_readiness.py
index 0c5aaf1..ac2d2aa 100644
--- a/services/market_intel/deployment_readiness.py
+++ b/services/market_intel/deployment_readiness.py
@@ -17,10 +17,11 @@ from services.market_intel.candidate_queue_review_decision import build_candidat
from services.market_intel.candidate_queue_review_decision_approval import build_candidate_queue_review_decision_approval
from services.market_intel.candidate_queue_review_decision_transaction import build_candidate_queue_review_decision_transaction
from services.market_intel.candidate_queue_review_decision_writer_cli import build_candidate_queue_review_decision_writer_cli_plan
+from services.market_intel.candidate_queue_review_decision_writer_preflight import build_candidate_queue_review_decision_writer_preflight
BLOCKED_RUN_REVIEW_KEYS = ("ready_for_api_database_write", "ready_for_scheduler_attach", "api_executes_cli", "api_reads_approval_token", "api_writes_file", "api_writes_database", "api_updates_review_state", "approval_record_written", "decision_record_written", "review_state_update_executed", "database_connection_opened", "database_session_created", "explicit_transaction_opened", "transaction_opened", "transaction_committed", "database_write_executed", "database_commit_executed", "database_rollback_executed", "scheduler_attached", "writes_executed", "would_write_database")
-PRODUCTION_SMOKE_TARGETS = ("/health", "/market_intel", "/api/market_intel/status", "/api/market_intel/deployment_readiness", "/api/market_intel/schema_smoke", "/api/market_intel/schema_db_probe", "/api/market_intel/platform_seed_db_diff", "/api/market_intel/legacy_source_bridge", "/api/market_intel/mcp_readiness", "/api/market_intel/mcp_tool_contract", "/api/market_intel/mcp_deploy_preflight", "/api/market_intel/mcp_activation_runbook", "/api/market_intel/mcp_fetch_gate", "/api/market_intel/scheduler_plan", "/api/market_intel/manual_sample_plan", "/api/market_intel/manual_sample_acceptance", "/api/market_intel/manual_sample_review", "/api/market_intel/match_review_plan", "/api/market_intel/opportunity_plan", "/api/market_intel/opportunity_scoring_plan", "/api/market_intel/opportunity_evidence_plan", "/api/market_intel/opportunity_alert_plan", "/api/market_intel/migration_apply_drill", "/api/market_intel/migration_catalog_review", "/api/market_intel/migration_live_smoke", "/api/market_intel/live_db_inventory", "/api/market_intel/manual_sample_review/candidate_queue_writer_postwrite_smoke", "/api/market_intel/manual_sample_review/candidate_queue_writer_operator_drill", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_package", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_readiness", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_receipt", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_closeout", "/api/market_intel/manual_sample_review/candidate_queue_review_handoff", "/api/market_intel/manual_sample_review/candidate_queue_review_inventory", "/api/market_intel/manual_sample_review/candidate_queue_review_decision", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status")
+PRODUCTION_SMOKE_TARGETS = ("/health", "/market_intel", "/api/market_intel/status", "/api/market_intel/deployment_readiness", "/api/market_intel/schema_smoke", "/api/market_intel/schema_db_probe", "/api/market_intel/platform_seed_db_diff", "/api/market_intel/legacy_source_bridge", "/api/market_intel/mcp_readiness", "/api/market_intel/mcp_tool_contract", "/api/market_intel/mcp_deploy_preflight", "/api/market_intel/mcp_activation_runbook", "/api/market_intel/mcp_fetch_gate", "/api/market_intel/scheduler_plan", "/api/market_intel/manual_sample_plan", "/api/market_intel/manual_sample_acceptance", "/api/market_intel/manual_sample_review", "/api/market_intel/match_review_plan", "/api/market_intel/opportunity_plan", "/api/market_intel/opportunity_scoring_plan", "/api/market_intel/opportunity_evidence_plan", "/api/market_intel/opportunity_alert_plan", "/api/market_intel/migration_apply_drill", "/api/market_intel/migration_catalog_review", "/api/market_intel/migration_live_smoke", "/api/market_intel/live_db_inventory", "/api/market_intel/manual_sample_review/candidate_queue_writer_postwrite_smoke", "/api/market_intel/manual_sample_review/candidate_queue_writer_operator_drill", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_package", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_readiness", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_receipt", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_closeout", "/api/market_intel/manual_sample_review/candidate_queue_review_handoff", "/api/market_intel/manual_sample_review/candidate_queue_review_inventory", "/api/market_intel/manual_sample_review/candidate_queue_review_decision", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status")
def _run_review_preview_safe(payload, mode):
@@ -116,6 +117,7 @@ def build_deployment_readiness_preview(
candidate_queue_review_decision_approval = build_candidate_queue_review_decision_approval(review_decision=candidate_queue_review_decision)
candidate_queue_review_decision_transaction = build_candidate_queue_review_decision_transaction(decision_approval=candidate_queue_review_decision_approval)
candidate_queue_review_decision_writer_status = build_candidate_queue_review_decision_writer_cli_plan(transaction_preview=candidate_queue_review_decision_transaction)
+ candidate_queue_review_decision_writer_preflight = build_candidate_queue_review_decision_writer_preflight(writer_status=candidate_queue_review_decision_writer_status, transaction_preview=candidate_queue_review_decision_transaction)
checks = {
"schema_smoke_passed": bool(schema_smoke["passed"]),
"feature_flags_default_safe": bool(
@@ -354,6 +356,10 @@ def build_deployment_readiness_preview(
candidate_queue_review_decision_transaction,
"candidate_queue_review_decision_transaction_preview",
),
+ "candidate_queue_review_decision_writer_preflight_safe": _run_review_preview_safe(
+ candidate_queue_review_decision_writer_preflight,
+ "candidate_queue_review_decision_writer_preflight_preview",
+ ),
"candidate_queue_review_decision_writer_cli_status_safe": _run_review_preview_safe(
candidate_queue_review_decision_writer_status,
"candidate_queue_review_decision_writer_cli_blocked",
@@ -590,6 +596,7 @@ def build_deployment_readiness_preview(
"candidate_queue_review_decision": candidate_queue_review_decision,
"candidate_queue_review_decision_approval": candidate_queue_review_decision_approval,
"candidate_queue_review_decision_transaction": candidate_queue_review_decision_transaction,
+ "candidate_queue_review_decision_writer_preflight": candidate_queue_review_decision_writer_preflight,
"candidate_queue_review_decision_writer_status": candidate_queue_review_decision_writer_status,
"match_review_plan": match_review_plan,
"opportunity_plan": opportunity_plan,
diff --git a/services/market_intel/phase.py b/services/market_intel/phase.py
index 760cb2c..cf402a8 100644
--- a/services/market_intel/phase.py
+++ b/services/market_intel/phase.py
@@ -1,3 +1,3 @@
"""市場情報 rollout phase 單一來源。"""
-MARKET_INTEL_PHASE = "phase_69_candidate_queue_review_decision_writer_cli"
+MARKET_INTEL_PHASE = "phase_70_candidate_queue_review_decision_writer_preflight"
diff --git a/templates/market_intel/disabled.html b/templates/market_intel/disabled.html
index 26d75c7..ce1c18a 100644
--- a/templates/market_intel/disabled.html
+++ b/templates/market_intel/disabled.html
@@ -643,6 +643,9 @@
+
@@ -988,6 +991,7 @@
const sampleCandidateQueueReviewDecision = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision]') : null;
const sampleCandidateQueueReviewDecisionApproval = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-approval]') : null;
const sampleCandidateQueueReviewDecisionTransaction = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-transaction]') : null;
+ const sampleCandidateQueueReviewDecisionPreflight = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-preflight]') : null;
const sampleCandidateQueueReviewDecisionWriter = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-writer]') : null;
const sampleReviewEndpoint = "{{ url_for('market_intel.market_intel_manual_sample_review') }}";
const sampleReviewEvaluateEndpoint = "{{ url_for('market_intel.market_intel_manual_sample_review_evaluate') }}";
@@ -1008,6 +1012,7 @@
const sampleCandidateQueueReviewDecisionEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision') }}";
const sampleCandidateQueueReviewDecisionApprovalEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_approval') }}";
const sampleCandidateQueueReviewDecisionTransactionEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_transaction') }}";
+ const sampleCandidateQueueReviewDecisionPreflightEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_preflight') }}";
const sampleCandidateQueueReviewDecisionWriterEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_status') }}";
const schedulerMeta = schedulerRoot ? schedulerRoot.querySelector('[data-market-intel-scheduler-meta]') : null;
const schedulerBody = schedulerRoot ? schedulerRoot.querySelector('[data-market-intel-scheduler-body]') : null;
@@ -3604,6 +3609,135 @@
}
};
+ const renderCandidateQueueReviewDecisionPreflight = data => {
+ const blockers = (data.blocked_reasons || []).join(' / ');
+ const summary = data.statement_summary || {};
+ const payloads = summary.review_state_updates || [];
+ const contract = data.update_contract || {};
+ const catalog = data.catalog_probe_plan || {};
+ sampleReviewMeta.innerHTML = [
+ `mode=${data.mode || 'unknown'}`,
+ `payload=${data.preflight_payload_ready ? 'ready' : 'blocked'}`,
+ `statements=${summary.statement_count || 0}`,
+ `query=${data.read_only_query_executed ? 'yes' : 'no'}`,
+ `db_write=${data.database_write_executed ? 'yes' : 'no'}`
+ ].map(item => `${escapeHtml(item)}`).join('');
+ sampleReviewBody.innerHTML = `
+
此卡只檢查 review_state writer preflight;API/UI 不讀 token、不連 DB、不更新 review_state、不 commit、不掛 scheduler。${blockers ? `阻擋:${escapeHtml(blockers)}` : ''}
+
+
+
PREFLIGHT GATES
+
${
+ (data.preflight_gates || []).map(gate => `
+
+
+ ${escapeHtml(gate.key)}
+ ${escapeHtml(gate.label)}
+
+
${gate.passed ? 'PASS' : 'BLOCK'}
+
+ `).join('') || '
尚未提供 preflight gates。
'
+ }
+
+
+
CONTRACT
+
+ ${[
+ ['target_table', contract.target_table || data.target_table || 'unknown'],
+ ['operation', contract.statement_type || data.target_operation || 'unknown'],
+ ['lookup', contract.lookup || 'dedupe_key'],
+ ['current_state', contract.expected_current_review_state || 'needs_review'],
+ ['allowed_next_states', (contract.allowed_next_states || []).join(', ') || 'none']
+ ].map(([key, value]) => `
+
+
${escapeHtml(key)}
+
${escapeHtml(String(value))}
+
+ `).join('')}
+
+
+
+
CATALOG PLAN
+
+ ${[
+ ['mode', catalog.mode || 'planned_only'],
+ ['required_columns', (catalog.required_columns || []).join(', ') || 'none'],
+ ['unique_lookup', catalog.required_unique_lookup || 'dedupe_key'],
+ ['connection_opened', catalog.database_connection_opened],
+ ['query_executed', catalog.read_only_query_executed]
+ ].map(([key, value]) => `
+
+
${escapeHtml(key)}
+
${escapeHtml(String(value))}
+
+ `).join('')}
+
+
+
+
PAYLOAD
+
${
+ payloads.map(row => `
+
+
+ ${escapeHtml(row.dedupe_key || row.idempotency_key || 'unknown')}
+ ${escapeHtml(row.expected_current_review_state || 'unknown')} -> ${escapeHtml(row.next_review_state || 'none')}
+
+
${escapeHtml(row.operation || 'update')}
+
+ `).join('') || '
尚未提供 review_state update payload。
'
+ }
+
+
+
WRITE FLAGS
+
+ ${[
+ ['api_updates_review_state', data.api_updates_review_state],
+ ['review_state_update_executed', data.review_state_update_executed],
+ ['database_write', data.database_write_executed],
+ ['scheduler', data.scheduler_attached]
+ ].map(([key, value]) => `
+
+
${escapeHtml(key)}
+
${escapeHtml(String(value))}
+
+ `).join('')}
+
+
+
+ `;
+ };
+
+ const loadCandidateQueueReviewDecisionPreflight = async () => {
+ if (!sampleReviewMeta || !sampleReviewBody || !sampleReviewInput) return;
+ let parsed;
+ try {
+ parsed = JSON.parse(sampleReviewInput.value || '{}');
+ } catch (error) {
+ sampleReviewMeta.innerHTML = 'json_error';
+ sampleReviewBody.innerHTML = `JSON 格式錯誤:${escapeHtml(error.message)}
`;
+ return;
+ }
+ const body = parsed && parsed.sample_result ? parsed : { sample_result: parsed };
+ sampleReviewBody.innerHTML = '檢查 queue review decision writer preflight 中...
';
+ try {
+ const response = await fetch(sampleCandidateQueueReviewDecisionPreflightEndpoint, {
+ method: 'POST',
+ credentials: 'same-origin',
+ headers: {
+ 'Content-Type': 'application/json',
+ 'X-CSRFToken': csrfToken
+ },
+ body: JSON.stringify(body)
+ });
+ const data = await response.json();
+ if (!response.ok && !data.mode) throw new Error(`HTTP ${response.status}`);
+ renderCandidateQueueReviewDecisionPreflight(data);
+ } catch (error) {
+ sampleReviewMeta.innerHTML = 'error';
+ sampleReviewBody.innerHTML = `queue review decision writer preflight 失敗:${escapeHtml(error.message)}
`;
+ }
+ };
+
const renderCandidateQueueReviewDecisionWriter = data => {
const blockers = (data.blocked_reasons || []).join(' / ');
const summary = data.statement_summary || {};
@@ -5262,6 +5396,9 @@
if (sampleCandidateQueueReviewDecisionTransaction) {
sampleCandidateQueueReviewDecisionTransaction.addEventListener('click', loadCandidateQueueReviewDecisionTransaction);
}
+ if (sampleCandidateQueueReviewDecisionPreflight) {
+ sampleCandidateQueueReviewDecisionPreflight.addEventListener('click', loadCandidateQueueReviewDecisionPreflight);
+ }
if (sampleCandidateQueueReviewDecisionWriter) {
sampleCandidateQueueReviewDecisionWriter.addEventListener('click', loadCandidateQueueReviewDecisionWriter);
}
diff --git a/tests/test_market_intel_skeleton.py b/tests/test_market_intel_skeleton.py
index 9f2aa13..5377c21 100644
--- a/tests/test_market_intel_skeleton.py
+++ b/tests/test_market_intel_skeleton.py
@@ -836,10 +836,18 @@ def test_market_intel_preview_template_uses_safe_fetch_false_endpoint():
"market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_status"
in template
)
+ assert (
+ "market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_preflight"
+ in template
+ )
assert (
"data-market-intel-sample-candidate-queue-review-decision-writer"
in template
)
+ assert (
+ "data-market-intel-sample-candidate-queue-review-decision-preflight"
+ in template
+ )
assert "X-CSRFToken" in template
assert "market_intel.market_intel_scheduler_plan" in template
assert "market_intel.market_intel_match_review_plan" in template
@@ -876,7 +884,7 @@ def test_legacy_source_bridge_default_is_planned_only():
bridge = MarketIntelService().build_legacy_source_bridge()
assert bridge["mode"] == "legacy_source_bridge_planned"
- assert bridge["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert bridge["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert bridge["execute_requested"] is False
assert bridge["read_only_query_executed"] is False
assert bridge["database_connection_opened"] is False
@@ -1034,7 +1042,7 @@ def test_mcp_tool_contract_preview_is_read_only_and_whitelisted():
contract = MarketIntelService().build_mcp_tool_contract()
assert contract["mode"] == "mcp_tool_contract_preview"
- assert contract["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert contract["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert contract["caller"] == "market_intel"
assert contract["contract_ready"] is True
assert contract["blocked_reasons"] == []
@@ -1167,7 +1175,7 @@ def test_mcp_activation_runbook_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "mcp_activation_runbook_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["deployment_actions_executed"] is False
assert data["docker_command_executed"] is False
assert data["ssh_command_executed"] is False
@@ -1180,7 +1188,7 @@ def test_mcp_fetch_gate_default_blocks_external_fetch():
gate = MarketIntelService().build_mcp_fetch_gate(fetch_requested=True)
assert gate["mode"] == "mcp_fetch_gate_planned"
- assert gate["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert gate["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert gate["fetch_requested"] is True
assert gate["manual_fetch_gate_open"] is False
assert gate["network_request_allowed"] is False
@@ -1250,7 +1258,7 @@ def test_mcp_fetch_gate_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "mcp_fetch_gate_planned"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["fetch_requested"] is False
assert data["network_request_allowed"] is False
assert data["external_network_executed"] is False
@@ -1262,7 +1270,7 @@ def test_manual_sample_plan_preview_blocks_fetch_and_write():
plan = MarketIntelService().build_manual_sample_plan()
assert plan["mode"] == "manual_sample_fetch_plan_preview"
- assert plan["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert plan["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert plan["ready_for_manual_sample_fetch"] is False
assert plan["sample_fetch_executed"] is False
assert plan["external_network_executed"] is False
@@ -1310,7 +1318,7 @@ def test_manual_sample_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "manual_sample_fetch_plan_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["sample_fetch_executed"] is False
assert data["external_network_executed"] is False
assert data["database_write_executed"] is False
@@ -1321,7 +1329,7 @@ def test_manual_sample_acceptance_preview_blocks_candidate_import():
acceptance = MarketIntelService().build_manual_sample_acceptance()
assert acceptance["mode"] == "manual_sample_acceptance_preview"
- assert acceptance["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert acceptance["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert acceptance["contract_ready"] is True
assert acceptance["sample_result_loaded"] is False
assert acceptance["sample_result_accepted"] is False
@@ -1363,7 +1371,7 @@ def test_manual_sample_acceptance_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "manual_sample_acceptance_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["sample_result_loaded"] is False
assert data["candidate_import_allowed"] is False
assert data["external_network_executed"] is False
@@ -1375,7 +1383,7 @@ def test_manual_sample_review_preview_is_planned_until_result_loaded():
review = MarketIntelService().build_manual_sample_review()
assert review["mode"] == "manual_sample_review_preview"
- assert review["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert review["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert review["contract_ready"] is True
assert review["sample_result_loaded"] is False
assert review["sample_result_reviewed"] is False
@@ -1486,7 +1494,7 @@ def test_manual_sample_review_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "manual_sample_review_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["sample_result_loaded"] is False
assert data["sample_result_reviewed"] is False
assert data["candidate_import_allowed"] is False
@@ -1525,7 +1533,7 @@ def test_manual_sample_review_evaluation_preview_accepts_payload_without_persist
)
assert review["mode"] == "manual_sample_review_evaluation_preview"
- assert review["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert review["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert review["review_request_type"] == "operator_posted_json"
assert review["payload_received"] is True
assert review["payload_valid_json_object"] is True
@@ -1587,7 +1595,7 @@ def test_manual_sample_review_evaluate_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "manual_sample_review_evaluation_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["payload_received"] is True
assert data["payload_valid_json_object"] is True
assert data["payload_persisted"] is False
@@ -1667,7 +1675,7 @@ def test_manual_sample_candidate_handoff_preview_creates_candidates_without_pers
)
assert handoff["mode"] == "manual_sample_candidate_handoff_preview"
- assert handoff["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert handoff["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert handoff["payload_received"] is True
assert handoff["payload_valid_json_object"] is True
assert handoff["payload_persisted"] is False
@@ -1731,7 +1739,7 @@ def test_manual_sample_candidate_handoff_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "manual_sample_candidate_handoff_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["payload_received"] is True
assert data["handoff_ready"] is True
assert data["candidate_handoff_created"] is True
@@ -1790,7 +1798,7 @@ def test_manual_sample_candidate_queue_draft_preview_builds_review_items_without
)
assert queue_draft["mode"] == "manual_sample_candidate_queue_draft_preview"
- assert queue_draft["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert queue_draft["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert queue_draft["payload_received"] is True
assert queue_draft["payload_valid_json_object"] is True
assert queue_draft["payload_persisted"] is False
@@ -1864,7 +1872,7 @@ def test_manual_sample_candidate_queue_draft_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "manual_sample_candidate_queue_draft_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["payload_received"] is True
assert data["handoff_ready"] is True
assert data["queue_draft_ready"] is True
@@ -1927,7 +1935,7 @@ def test_manual_sample_candidate_queue_approval_preview_blocks_write_and_maps_ro
)
assert approval["mode"] == "manual_sample_candidate_queue_approval_preview"
- assert approval["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert approval["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert approval["payload_received"] is True
assert approval["payload_valid_json_object"] is True
assert approval["payload_persisted"] is False
@@ -2005,7 +2013,7 @@ def test_manual_sample_candidate_queue_approval_route_is_post_only_and_no_write(
assert response.status_code == 200
assert data["mode"] == "manual_sample_candidate_queue_approval_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["payload_received"] is True
assert data["approval_preview_created"] is True
assert data["approval_request_created"] is False
@@ -2068,7 +2076,7 @@ def test_manual_sample_candidate_queue_transaction_preview_blocks_execution():
)
assert transaction["mode"] == "manual_sample_candidate_queue_transaction_preview"
- assert transaction["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert transaction["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert transaction["payload_received"] is True
assert transaction["payload_valid_json_object"] is True
assert transaction["payload_persisted"] is False
@@ -2148,7 +2156,7 @@ def test_manual_sample_candidate_queue_transaction_route_is_post_only_and_no_wri
assert response.status_code == 200
assert data["mode"] == "manual_sample_candidate_queue_transaction_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["payload_received"] is True
assert data["transaction_preview_created"] is True
assert data["transaction_ready"] is False
@@ -3867,6 +3875,83 @@ def test_candidate_queue_review_decision_writer_cli_gate_is_non_writing():
assert TEST_APPROVAL_TOKEN not in payload
+def test_candidate_queue_review_decision_writer_preflight_is_payload_only():
+ from services.market_intel.candidate_queue_review_decision_writer_cli import (
+ build_candidate_queue_review_decision_writer_cli_plan,
+ )
+ from services.market_intel.candidate_queue_review_decision_writer_preflight import (
+ build_candidate_queue_review_decision_writer_preflight,
+ )
+
+ transaction, operator_evidence = _build_ready_review_decision_transaction()
+ writer_status = build_candidate_queue_review_decision_writer_cli_plan(
+ transaction_preview=transaction,
+ execute_requested=False,
+ apply_real_write=False,
+ )
+ preflight = build_candidate_queue_review_decision_writer_preflight(
+ writer_status=writer_status,
+ transaction_preview=transaction,
+ operator_evidence={
+ **operator_evidence,
+ "operator_confirmed_review_state_preflight_only": True,
+ },
+ )
+ token_leak = build_candidate_queue_review_decision_writer_preflight(
+ writer_status=writer_status,
+ transaction_preview=transaction,
+ operator_evidence={**operator_evidence, "approval_token": TEST_APPROVAL_TOKEN},
+ )
+ payload = json.dumps(preflight, ensure_ascii=False, sort_keys=True)
+
+ assert preflight["mode"] == (
+ "candidate_queue_review_decision_writer_preflight_preview"
+ )
+ assert preflight["target_table"] == "market_alert_review_queue"
+ assert preflight["target_operation"] == "update_review_state"
+ assert preflight["execute_requested"] is False
+ assert preflight["apply_real_write_requested"] is False
+ assert preflight["preflight_payload_ready"] is True
+ assert preflight["writer_status_safe"] is True
+ assert preflight["writer_implementation_enabled"] is False
+ assert preflight["preflight_ready"] is False
+ assert preflight["ready_for_real_write"] is False
+ assert preflight["ready_for_api_review_state_update"] is False
+ assert preflight["ready_for_api_database_write"] is False
+ assert preflight["api_executes_cli"] is False
+ assert preflight["api_reads_approval_token"] is False
+ assert preflight["api_writes_database"] is False
+ assert preflight["api_updates_review_state"] is False
+ assert preflight["review_state_update_executed"] is False
+ assert preflight["read_only_query_executed"] is False
+ assert preflight["database_connection_opened"] is False
+ assert preflight["database_session_created"] is False
+ assert preflight["transaction_opened"] is False
+ assert preflight["transaction_committed"] is False
+ assert preflight["database_write_executed"] is False
+ assert preflight["database_commit_executed"] is False
+ assert preflight["scheduler_attached"] is False
+ assert preflight["writes_executed"] is False
+ assert preflight["would_write_database"] is False
+ assert preflight["statement_summary"]["statement_count"] == 1
+ assert preflight["statement_summary"]["invalid_statement_count"] == 0
+ assert preflight["statement_summary"]["review_state_updates"][0][
+ "next_review_state"
+ ] == "confirmed"
+ assert preflight["update_contract"]["expected_current_review_state"] == (
+ "needs_review"
+ )
+ assert preflight["catalog_probe_plan"]["read_only_query_executed"] is False
+ assert "review_decision_writer_implementation_enabled" in preflight[
+ "blocked_reasons"
+ ]
+ assert "do_not_update_review_state_from_review_state_preflight" in preflight[
+ "safe_boundaries"
+ ]
+ assert "preflight_no_token_submitted_to_api" in token_leak["blocked_reasons"]
+ assert TEST_APPROVAL_TOKEN not in payload
+
+
def test_candidate_queue_writer_preflight_route_is_post_only_and_no_write():
from routes.market_intel_routes import market_intel_bp
@@ -3909,7 +3994,7 @@ def test_candidate_queue_writer_preflight_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_preflight_planned"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["read_only_query_executed"] is False
assert data["database_connection_opened"] is False
@@ -3966,7 +4051,7 @@ def test_candidate_queue_writer_status_route_never_leaks_approval_token(monkeypa
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_cli_blocked"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is True
assert data["apply_real_write_requested"] is True
assert data["approval_token_present"] is False
@@ -4055,7 +4140,7 @@ def test_candidate_queue_writer_postwrite_smoke_route_is_post_only_and_no_write(
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_postwrite_smoke_planned"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["read_only_query_executed"] is False
assert data["database_connection_opened"] is False
@@ -4109,7 +4194,7 @@ def test_candidate_queue_writer_operator_drill_route_is_post_only_and_no_write()
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_operator_drill_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["operator_drill_ready"] is True
assert data["api_executes_cli"] is False
assert data["api_reads_approval_token"] is False
@@ -4165,7 +4250,7 @@ def test_candidate_queue_writer_run_package_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_package_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["package_ready"] is True
assert data["package_artifact_created"] is False
assert data["api_writes_file"] is False
@@ -4231,7 +4316,7 @@ def test_candidate_queue_writer_run_readiness_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_readiness_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["ready_for_cli_operator_run"] is True
assert data["ready_for_api_database_write"] is False
assert data["api_executes_cli"] is False
@@ -4533,7 +4618,7 @@ def test_candidate_queue_writer_run_receipt_route_accepts_inline_payload_no_writ
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_receipt_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["receipt_passed"] is True
assert data["ready_for_api_database_write"] is False
assert data["ready_for_scheduler_attach"] is False
@@ -4581,7 +4666,7 @@ def test_candidate_queue_writer_run_closeout_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_closeout_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["closeout_passed"] is True
assert data["ready_for_next_manual_phase"] is True
assert data["ready_for_api_database_write"] is False
@@ -4630,7 +4715,7 @@ def test_candidate_queue_review_handoff_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_handoff_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["handoff_ready"] is True
assert data["ready_for_manual_queue_review"] is True
assert data["ready_for_api_database_write"] is False
@@ -4688,7 +4773,7 @@ def test_candidate_queue_review_inventory_route_is_post_only_and_no_write():
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_inventory_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["review_inventory_ready"] is False
assert data["ready_for_human_decision_review"] is False
@@ -4754,7 +4839,7 @@ def test_candidate_queue_review_decision_route_is_post_only_and_no_write():
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_decision_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["decision_ready"] is False
assert data["ready_for_human_decision_record"] is False
assert data["ready_for_api_review_state_update"] is False
@@ -4825,7 +4910,7 @@ def test_candidate_queue_review_decision_approval_route_is_post_only_and_no_writ
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_decision_approval_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["approval_ready"] is False
assert data["ready_for_review_state_transaction_preview"] is False
assert data["ready_for_cli_decision_writer"] is False
@@ -4901,7 +4986,7 @@ def test_candidate_queue_review_decision_transaction_route_is_post_only_and_no_w
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_decision_transaction_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["transaction_preview_created"] is False
assert data["transaction_ready"] is False
assert data["ready_for_manual_shell_update_window"] is False
@@ -4983,7 +5068,7 @@ def test_candidate_queue_review_decision_writer_status_route_is_post_only_and_no
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_decision_writer_cli_blocked"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is True
assert data["apply_real_write_requested"] is True
assert data["approval_token_present"] is False
@@ -5014,6 +5099,90 @@ def test_candidate_queue_review_decision_writer_status_route_is_post_only_and_no
]
+def test_candidate_queue_review_decision_writer_preflight_route_is_post_only_and_no_write():
+ from routes.market_intel_routes import market_intel_bp
+ from routes.market_intel_review_routes import market_intel_review_bp
+
+ fixture = _build_candidate_queue_writer_receipt_fixture(
+ "sample-batch-review-decision-preflight-route"
+ )
+ app = Flask(__name__)
+ app.secret_key = "test-secret"
+ app.register_blueprint(market_intel_bp)
+ app.register_blueprint(market_intel_review_bp)
+ client = app.test_client()
+ with client.session_transaction() as session:
+ session["logged_in"] = True
+
+ get_response = client.get(
+ "/api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_preflight"
+ )
+ response = client.post(
+ "/api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_preflight?execute=true"
+ "&apply_real_write=true",
+ json={
+ "sample_result": fixture["sample_result"],
+ "operator_evidence": {
+ **fixture["operator_evidence"],
+ "closeout_artifact_path": "artifacts/market_intel/closeout.json",
+ "operator_confirmed_queue_review_next": True,
+ "operator_confirmed_no_scheduler_attach": True,
+ "operator_confirmed_no_api_db_write": True,
+ "operator_confirmed_inventory_read_only": True,
+ "reviewer_id": "operator-a",
+ "proposed_review_decision": "confirmed",
+ "decision_notes": "manual review only",
+ "operator_confirmed_manual_decision_only": True,
+ "decision_approval_notes": "cli-only approval gate",
+ "operator_confirmed_decision_payload_reviewed": True,
+ "operator_confirmed_decision_apply_requires_cli": True,
+ "operator_confirmed_review_state_update_is_not_api": True,
+ "decision_transaction_notes": "shell-only transaction preview",
+ "operator_confirmed_transaction_payload_reviewed": True,
+ "operator_confirmed_cli_only_transaction": True,
+ },
+ "writer_output": fixture["writer_output"],
+ "postwrite_smoke_result": fixture["postwrite_smoke_result"],
+ },
+ )
+ data = response.get_json()
+
+ assert get_response.status_code == 405
+ assert response.status_code == 200
+ assert data["mode"] == (
+ "candidate_queue_review_decision_writer_preflight_preview"
+ )
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
+ assert data["execute_requested"] is True
+ assert data["apply_real_write_requested"] is True
+ assert data["read_only_query_executed"] is False
+ assert data["database_connection_opened"] is False
+ assert data["database_session_created"] is False
+ assert data["explicit_transaction_opened"] is False
+ assert data["transaction_opened"] is False
+ assert data["transaction_committed"] is False
+ assert data["database_write_executed"] is False
+ assert data["database_commit_executed"] is False
+ assert data["review_state_update_executed"] is False
+ assert data["api_updates_review_state"] is False
+ assert data["scheduler_attached"] is False
+ assert data["writes_executed"] is False
+ assert data["would_write_database"] is False
+ assert data["preflight_payload_ready"] is False
+ assert data["statement_summary"]["statement_count"] == 0
+ assert "statement_payloads_present" in data["blocked_reasons"]
+ assert "preflight_execute_not_requested_from_api" in data["blocked_reasons"]
+ assert "preflight_apply_real_write_not_requested_from_api" in data[
+ "blocked_reasons"
+ ]
+ assert "review_decision_writer_implementation_enabled" in data["blocked_reasons"]
+ assert "do_not_update_review_state_from_review_state_preflight" in data[
+ "safe_boundaries"
+ ]
+
+
def test_candidate_queue_writer_run_receipt_route_is_post_only_and_no_write():
from routes.market_intel_routes import market_intel_bp
@@ -5042,7 +5211,7 @@ def test_candidate_queue_writer_run_receipt_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_receipt_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["receipt_passed"] is True
assert data["ready_for_next_manual_review"] is True
assert data["ready_for_api_database_write"] is False
@@ -5067,7 +5236,7 @@ def test_scheduler_plan_preview_blocks_job_attachment():
plan = MarketIntelService().build_scheduler_plan()
assert plan["mode"] == "scheduler_attach_plan_preview"
- assert plan["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert plan["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert plan["ready_to_attach_scheduler"] is False
assert plan["scheduler_attached"] is False
assert plan["scheduler_registration_executed"] is False
@@ -5105,7 +5274,7 @@ def test_scheduler_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "scheduler_attach_plan_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["scheduler_registration_executed"] is False
assert data["crawler_job_started"] is False
assert data["external_network_executed"] is False
@@ -5116,7 +5285,7 @@ def test_match_review_plan_preview_blocks_auto_confirm():
plan = MarketIntelService().build_match_review_plan()
assert plan["mode"] == "match_review_plan_preview"
- assert plan["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert plan["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert plan["ready_for_review_queue"] is False
assert plan["review_queue_created"] is False
assert plan["auto_match_executed"] is False
@@ -5152,7 +5321,7 @@ def test_match_review_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "match_review_plan_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["review_queue_created"] is False
assert data["auto_confirm_executed"] is False
assert data["external_network_executed"] is False
@@ -5163,7 +5332,7 @@ def test_opportunity_plan_preview_blocks_alerts_and_ai_summary():
plan = MarketIntelService().build_opportunity_plan()
assert plan["mode"] == "opportunity_plan_preview"
- assert plan["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert plan["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert plan["ready_for_opportunity_queue"] is False
assert plan["opportunity_queue_created"] is False
assert plan["threat_alert_dispatched"] is False
@@ -5204,7 +5373,7 @@ def test_opportunity_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "opportunity_plan_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["opportunity_queue_created"] is False
assert data["threat_alert_dispatched"] is False
assert data["ai_summary_generated"] is False
@@ -5215,7 +5384,7 @@ def test_opportunity_scoring_plan_preview_blocks_scoring_and_alerts():
plan = MarketIntelService().build_opportunity_scoring_plan()
assert plan["mode"] == "opportunity_scoring_plan_preview"
- assert plan["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert plan["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert plan["ready_for_scoring_job"] is False
assert plan["scoring_job_created"] is False
assert plan["score_calculation_executed"] is False
@@ -5263,7 +5432,7 @@ def test_opportunity_scoring_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "opportunity_scoring_plan_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["scoring_job_created"] is False
assert data["score_calculation_executed"] is False
assert data["sample_scores_generated"] is False
@@ -5275,7 +5444,7 @@ def test_opportunity_evidence_plan_preview_blocks_queries_and_alerts():
plan = MarketIntelService().build_opportunity_evidence_plan()
assert plan["mode"] == "opportunity_evidence_plan_preview"
- assert plan["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert plan["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert plan["ready_for_evidence_bundle"] is False
assert plan["evidence_bundle_created"] is False
assert plan["evidence_query_executed"] is False
@@ -5321,7 +5490,7 @@ def test_opportunity_evidence_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "opportunity_evidence_plan_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["evidence_bundle_created"] is False
assert data["evidence_query_executed"] is False
assert data["sample_evidence_generated"] is False
@@ -5334,7 +5503,7 @@ def test_opportunity_alert_plan_preview_blocks_dispatch_and_llm_calls():
plan = MarketIntelService().build_opportunity_alert_plan()
assert plan["mode"] == "opportunity_alert_plan_preview"
- assert plan["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert plan["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert plan["ready_for_alert_candidates"] is False
assert plan["alert_candidate_created"] is False
assert plan["alert_queue_created"] is False
@@ -5419,7 +5588,7 @@ def test_opportunity_alert_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "opportunity_alert_plan_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["alert_candidate_created"] is False
assert data["alert_queue_created"] is False
assert data["review_queue_created"] is False
@@ -5497,7 +5666,7 @@ def test_mcp_deploy_preflight_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "mcp_external_deploy_preflight_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["deployment_actions_executed"] is False
assert data["docker_command_executed"] is False
assert data["ssh_command_executed"] is False
@@ -5512,7 +5681,7 @@ def test_mcp_readiness_default_is_planned_only(monkeypatch):
readiness = MarketIntelService().build_mcp_readiness()
assert readiness["mode"] == "mcp_readiness_planned"
- assert readiness["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert readiness["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert readiness["execute_requested"] is False
assert readiness["router_enabled"] is False
assert readiness["external_mcp_complete"] is False
@@ -5958,6 +6127,12 @@ def test_deployment_readiness_reports_app_only_release_gate():
]
is True
)
+ assert (
+ readiness["checks"][
+ "candidate_queue_review_decision_writer_preflight_safe"
+ ]
+ is True
+ )
assert (
readiness["checks"][
"candidate_queue_review_decision_writer_cli_status_safe"
@@ -6052,6 +6227,11 @@ def test_deployment_readiness_reports_app_only_release_gate():
"candidate_queue_review_decision_transaction"
in readiness["production_smoke_targets"]
)
+ assert (
+ "/api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_preflight"
+ in readiness["production_smoke_targets"]
+ )
assert (
"/api/market_intel/manual_sample_review/"
"candidate_queue_review_decision_writer_status"
@@ -6837,6 +7017,64 @@ def test_deployment_readiness_reports_app_only_release_gate():
]
is False
)
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"]["mode"]
+ == "candidate_queue_review_decision_writer_preflight_preview"
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "preflight_payload_ready"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "ready_for_api_review_state_update"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "api_updates_review_state"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "read_only_query_executed"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "database_connection_opened"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "database_write_executed"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "database_commit_executed"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "review_state_update_executed"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_preflight"][
+ "scheduler_attached"
+ ]
+ is False
+ )
assert (
readiness["candidate_queue_review_decision_writer_status"]["mode"]
== "candidate_queue_review_decision_writer_cli_blocked"
@@ -6987,7 +7225,7 @@ def test_migration_apply_drill_planned_is_safe_and_manual_only():
drill = MarketIntelService().build_migration_apply_drill()
assert drill["mode"] == "migration_apply_drill_preview"
- assert drill["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert drill["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert drill["execute_requested"] is False
assert drill["schema_state"] == "planned_no_db_probe"
assert drill["drill_ready_for_operator_review"] is True
@@ -7102,7 +7340,7 @@ def test_migration_apply_drill_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "migration_apply_drill_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["migration_executed"] is False
assert data["rollback_executed"] is False
@@ -7114,7 +7352,7 @@ def test_migration_catalog_review_planned_is_safe_and_diagnostic():
review = MarketIntelService().build_migration_catalog_review()
assert review["mode"] == "migration_catalog_review_preview"
- assert review["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert review["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert review["execute_requested"] is False
assert review["catalog_state"] == "planned_no_probe"
assert review["seed_state"] == "planned_no_probe"
@@ -7229,7 +7467,7 @@ def test_migration_catalog_review_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "migration_catalog_review_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["catalog_state"] == "planned_no_probe"
assert data["migration_executed"] is False
@@ -7242,7 +7480,7 @@ def test_migration_live_smoke_planned_is_preview_only():
smoke = MarketIntelService().build_migration_live_smoke()
assert smoke["mode"] == "migration_live_smoke_preview"
- assert smoke["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert smoke["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert smoke["execute_requested"] is False
assert smoke["smoke_result"] == "planned_no_execution"
assert smoke["live_smoke_passed"] is False
@@ -7304,7 +7542,7 @@ def test_migration_live_smoke_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "migration_live_smoke_preview"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["smoke_result"] == "planned_no_execution"
assert data["migration_executed"] is False
@@ -7317,7 +7555,7 @@ def test_live_db_inventory_planned_is_preview_only():
inventory = MarketIntelService().build_live_db_inventory()
assert inventory["mode"] == "live_db_inventory_planned"
- assert inventory["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert inventory["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert inventory["execute_requested"] is False
assert inventory["read_only_query_executed"] is False
assert inventory["database_connection_opened"] is False
@@ -7461,7 +7699,7 @@ def test_live_db_inventory_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "live_db_inventory_planned"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["read_only_query_executed"] is False
assert data["database_write_executed"] is False
@@ -7688,7 +7926,7 @@ def test_candidate_queue_writer_cli_script_outputs_blocked_gate(tmp_path):
assert result.returncode == 0
assert data["mode"] == "candidate_queue_writer_cli_blocked"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["apply_real_write_requested"] is False
assert data["writes_executed"] is False
@@ -7717,7 +7955,7 @@ def test_review_decision_writer_cli_script_outputs_blocked_gate_without_login_en
assert result.returncode == 0
assert data["mode"] == "candidate_queue_review_decision_writer_cli_blocked"
- assert data["phase"] == "phase_69_candidate_queue_review_decision_writer_cli"
+ assert data["phase"] == "phase_70_candidate_queue_review_decision_writer_preflight"
assert data["execute_requested"] is False
assert data["apply_real_write_requested"] is False
assert data["approval_token_present"] is False