diff --git a/TODO_NEXT_STEPS.txt b/TODO_NEXT_STEPS.txt
index b4c6ee0..d41bcd8 100644
--- a/TODO_NEXT_STEPS.txt
+++ b/TODO_NEXT_STEPS.txt
@@ -144,6 +144,7 @@
- Phase 70 candidate queue review decision writer preflight:新增 `services/market_intel/candidate_queue_review_decision_writer_preflight.py`、POST `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight` 與 UI preflight 按鈕,檢查 writer status、review_state update payload、狀態轉換與禁止 token 進 API;API/UI 即使收到 execute/apply_real_write 也不連 DB、不執行 CLI、不更新 review_state、不 commit、不讀 token、不掛 scheduler;版本同步至 V10.258。
- V10.259 補 Phase 70 preflight 合約與 OCLearn queue 時區:preflight 補 planned/read-only catalog probe 欄位、dedupe unique index 檢查與 route 重複註冊清理;OCLearn embedding queue 的 created_at/updated_at/stale cutoff 改為台北 naive,避免 UTC/台北時間差讓 processing 任務卡住。
- Phase 71 candidate queue review decision writer post-write smoke:新增 `services/market_intel/candidate_queue_review_decision_writer_postwrite_smoke.py`、POST `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_postwrite_smoke` 與 UI smoke 按鈕,人工 CLI 更新 review_state 後可用 dedupe key 只讀驗證 row 是否存在且 state 符合預期;API/UI 預設不連 DB,execute=true 也只讀查詢,不更新 review_state、不 commit、不讀 token、不掛 scheduler;版本同步至 V10.260。
+ - Phase 72 candidate queue review decision writer operator drill:新增 `services/market_intel/candidate_queue_review_decision_writer_operator_drill.py`、POST `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_operator_drill` 與 UI drill 按鈕,將 review_state CLI 更新前後的 transaction JSON、備份、preflight、CLI writer、post-write smoke 與 rollback plan 組成可稽核操作順序;API/UI 不讀 token、不執行 CLI、不連 DB、不更新 review_state、不 commit、不掛 scheduler;版本同步至 V10.261。
- V10.248 補市場情報 390px preview panel QA:sample review 工具列改為 textarea + 可換行 action rail,移除舊的硬編 8 欄 grid;`check_responsive_overflow` 新增 `--screenshot-all`,本機 390x844 `/market_intel` 真頁面 QA 通過且 overflow=0。
- V10.250 補 Code Review Gemini 備援遙測護欄:Ollama 主路徑失敗時 `fallback_to` 明確指向 `code_review_openclaw_gemini`,測試鎖住「Gemini 不得記成 `code_review_openclaw` 主 caller」;AI Calls 觀測台會把 legacy `code_review_openclaw + gemini` 顯示成 Gemini 備援,避免誤判 Gemini-first。
- Schema smoke:`tests/test_market_intel_skeleton.py` 檢查 `Base.metadata` 內含 ADR-035 八張 `market_*` tables。
diff --git a/config.py b/config.py
index 62d5166..e2faf56 100644
--- a/config.py
+++ b/config.py
@@ -320,7 +320,7 @@ YOUTUBE_API_KEY = os.getenv('YOUTUBE_API_KEY', '')
# ==========================================
# 系統版本與路徑
# ==========================================
-SYSTEM_VERSION = "V10.260"
+SYSTEM_VERSION = "V10.261"
LOG_FILE_PATH = os.path.join(BASE_DIR, 'logs/system.log')
public_url = PUBLIC_URL # 用於模板顯示
diff --git a/docs/adr/ADR-035-cross-platform-market-campaign-intelligence.md b/docs/adr/ADR-035-cross-platform-market-campaign-intelligence.md
index 90f3a02..7009e57 100644
--- a/docs/adr/ADR-035-cross-platform-market-campaign-intelligence.md
+++ b/docs/adr/ADR-035-cross-platform-market-campaign-intelligence.md
@@ -197,6 +197,7 @@ EwoooC 目前已有 MOMO EDM / 節慶活動資料、`promo_products`、PChome
- 2026-05-19 追加 candidate queue review decision writer CLI gate:`services.market_intel.candidate_queue_review_decision_writer_cli`、`scripts/market_intel_review_decision_writer.py` 與 `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status` 先建立 review_state writer 的 shell-only gate、一次性 token env var、command bundle 與 rollback plan。此階段 writer implementation 保持 disabled;API/UI 不讀 approval token、不執行 CLI、不連 DB、不開 transaction、不 commit、不更新 `review_state`、不掛 scheduler。
- 2026-05-19 追加 candidate queue review decision writer preflight:`services.market_intel.candidate_queue_review_decision_writer_preflight` 與 `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight` 檢查 writer status、review_state update payload、狀態轉換與 token 外洩風險。API/UI 即使收到 `execute=true` 或 `apply_real_write=true` 也只回 blocked preview,不連 DB、不執行 CLI、不更新 `review_state`、不 commit、不讀 approval token、不掛 scheduler。
- 2026-05-19 追加 candidate queue review decision writer post-write smoke:`services.market_intel.candidate_queue_review_decision_writer_postwrite_smoke` 與 `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_postwrite_smoke` 依 review_state transaction preview 的 dedupe key 只讀查詢 `market_alert_review_queue`,確認人工 CLI 更新後的 `review_state` 是否符合預期。UI 預設 `execute=false` 不連 DB;人工 smoke 即使 `execute=true` 也只讀查詢,不更新 `review_state`、不 commit、不讀 approval token、不掛 scheduler。
+- 2026-05-19 追加 candidate queue review decision writer operator drill:`services.market_intel.candidate_queue_review_decision_writer_operator_drill` 與 `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_operator_drill` 整理 review_state CLI 更新前後的操作員順序、preflight、post-write smoke、gate 與 rollback plan。此 drill 只輸出可稽核操作計畫;API/UI 不讀 approval token、不執行 CLI、不連 DB、不更新 `review_state`、不 commit、不掛 scheduler。
### Phase 4:Coupang / Shopee Adapter
diff --git a/routes/README.md b/routes/README.md
index 568273d..b7a1eb2 100644
--- a/routes/README.md
+++ b/routes/README.md
@@ -19,8 +19,8 @@
| `edm_routes.py` | EDM 與節慶儀表板 | `/edm`, `/festival` |
| `monthly_routes.py` | 月結分析 | `/monthly_summary_analysis`, `/api/monthly_summary_data` |
| `daily_sales_routes.py` | 當日業績 | `/daily_sales`, `/daily_sales/export*` |
-| `market_intel_routes.py` | 市場情報 Phase 71 candidate queue review decision writer post-write smoke 主路由 | `/market_intel`, `/market_intel/*`, `/api/market_intel/status`, `/api/market_intel/schema`, `/api/market_intel/schema_smoke`, `/api/market_intel/schema_db_probe`, `/api/market_intel/platform_seed_db_diff`, `/api/market_intel/legacy_source_bridge`, `/api/market_intel/mcp_readiness`, `/api/market_intel/mcp_tool_contract`, `/api/market_intel/mcp_deploy_preflight`, `/api/market_intel/mcp_activation_runbook`, `/api/market_intel/mcp_fetch_gate`, `/api/market_intel/scheduler_plan`, `/api/market_intel/manual_sample_plan`, `/api/market_intel/manual_sample_acceptance`, `/api/market_intel/manual_sample_review`, `/api/market_intel/manual_sample_review/evaluate`, `/api/market_intel/manual_sample_review/candidate_handoff`, `/api/market_intel/manual_sample_review/candidate_queue_draft`, `/api/market_intel/manual_sample_review/candidate_queue_approval`, `/api/market_intel/manual_sample_review/candidate_queue_transaction`, `/api/market_intel/manual_sample_review/candidate_queue_writer_status`, `/api/market_intel/manual_sample_review/candidate_queue_writer_preflight`, `/api/market_intel/manual_sample_review/candidate_queue_writer_postwrite_smoke`, `/api/market_intel/manual_sample_review/candidate_queue_writer_operator_drill`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_package`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_readiness`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_receipt`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_closeout`, `/api/market_intel/manual_sample_review/candidate_queue_review_handoff`, `/api/market_intel/match_review_plan`, `/api/market_intel/opportunity_plan`, `/api/market_intel/opportunity_scoring_plan`, `/api/market_intel/opportunity_evidence_plan`, `/api/market_intel/opportunity_alert_plan`, `/api/market_intel/adapters`, `/api/market_intel/dry_run_plan`, `/api/market_intel/discovery_plan`, `/api/market_intel/manual_discovery`, `/api/market_intel/candidate_preview`, `/api/market_intel/platform_seed_plan`, `/api/market_intel/platform_seed_write_guard`, `/api/market_intel/platform_seed_writer_plan`, `/api/market_intel/migration_blueprint`, `/api/market_intel/migration_apply_drill`, `/api/market_intel/migration_catalog_review`, `/api/market_intel/migration_live_smoke`, `/api/market_intel/live_db_inventory`, `/api/market_intel/seed_writer_cli_status`, `/api/market_intel/write_approval_runbook`, `/api/market_intel/deployment_readiness` |
-| `market_intel_review_routes.py` | 市場情報人工 queue review 只讀延伸 API | `/api/market_intel/manual_sample_review/candidate_queue_review_inventory`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_postwrite_smoke` |
+| `market_intel_routes.py` | 市場情報 Phase 72 candidate queue review decision writer operator drill 主路由 | `/market_intel`, `/market_intel/*`, `/api/market_intel/status`, `/api/market_intel/schema`, `/api/market_intel/schema_smoke`, `/api/market_intel/schema_db_probe`, `/api/market_intel/platform_seed_db_diff`, `/api/market_intel/legacy_source_bridge`, `/api/market_intel/mcp_readiness`, `/api/market_intel/mcp_tool_contract`, `/api/market_intel/mcp_deploy_preflight`, `/api/market_intel/mcp_activation_runbook`, `/api/market_intel/mcp_fetch_gate`, `/api/market_intel/scheduler_plan`, `/api/market_intel/manual_sample_plan`, `/api/market_intel/manual_sample_acceptance`, `/api/market_intel/manual_sample_review`, `/api/market_intel/manual_sample_review/evaluate`, `/api/market_intel/manual_sample_review/candidate_handoff`, `/api/market_intel/manual_sample_review/candidate_queue_draft`, `/api/market_intel/manual_sample_review/candidate_queue_approval`, `/api/market_intel/manual_sample_review/candidate_queue_transaction`, `/api/market_intel/manual_sample_review/candidate_queue_writer_status`, `/api/market_intel/manual_sample_review/candidate_queue_writer_preflight`, `/api/market_intel/manual_sample_review/candidate_queue_writer_postwrite_smoke`, `/api/market_intel/manual_sample_review/candidate_queue_writer_operator_drill`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_package`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_readiness`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_receipt`, `/api/market_intel/manual_sample_review/candidate_queue_writer_run_closeout`, `/api/market_intel/manual_sample_review/candidate_queue_review_handoff`, `/api/market_intel/match_review_plan`, `/api/market_intel/opportunity_plan`, `/api/market_intel/opportunity_scoring_plan`, `/api/market_intel/opportunity_evidence_plan`, `/api/market_intel/opportunity_alert_plan`, `/api/market_intel/adapters`, `/api/market_intel/dry_run_plan`, `/api/market_intel/discovery_plan`, `/api/market_intel/manual_discovery`, `/api/market_intel/candidate_preview`, `/api/market_intel/platform_seed_plan`, `/api/market_intel/platform_seed_write_guard`, `/api/market_intel/platform_seed_writer_plan`, `/api/market_intel/migration_blueprint`, `/api/market_intel/migration_apply_drill`, `/api/market_intel/migration_catalog_review`, `/api/market_intel/migration_live_smoke`, `/api/market_intel/live_db_inventory`, `/api/market_intel/seed_writer_cli_status`, `/api/market_intel/write_approval_runbook`, `/api/market_intel/deployment_readiness` |
+| `market_intel_review_routes.py` | 市場情報人工 queue review 只讀延伸 API | `/api/market_intel/manual_sample_review/candidate_queue_review_inventory`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_postwrite_smoke`, `/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_operator_drill` |
| `api_routes.py` | 通用任務與查詢 API | `/api/run_task`, `/api/history/*` |
| `export_routes.py` | 匯出功能 | `/api/export/*` |
| `import_routes.py` | 匯入功能 | `/api/import_excel`, `/api/import/monthly_summary` |
diff --git a/routes/market_intel_review_routes.py b/routes/market_intel_review_routes.py
index 0e7ef73..020d606 100644
--- a/routes/market_intel_review_routes.py
+++ b/routes/market_intel_review_routes.py
@@ -30,6 +30,9 @@ from services.market_intel.candidate_queue_review_decision_writer_preflight impo
from services.market_intel.candidate_queue_review_decision_writer_postwrite_smoke import (
build_candidate_queue_review_decision_writer_postwrite_smoke,
)
+from services.market_intel.candidate_queue_review_decision_writer_operator_drill import (
+ build_candidate_queue_review_decision_writer_operator_drill,
+)
from services.market_intel.candidate_queue_writer_cli import (
build_candidate_queue_writer_cli_plan,
)
@@ -238,6 +241,80 @@ def _build_review_decision_transaction_stack(
)
+def _live_inventory_from_postwrite_smoke(postwrite_smoke_result):
+ postwrite_smoke_result = (
+ postwrite_smoke_result if isinstance(postwrite_smoke_result, dict) else {}
+ )
+ row_summaries = postwrite_smoke_result.get("row_summaries") or []
+ return {
+ "mode": "live_db_inventory_from_postwrite_smoke_preview",
+ "summary_ready": bool(postwrite_smoke_result.get("postwrite_smoke_passed")),
+ "read_only_query_executed": bool(
+ postwrite_smoke_result.get("read_only_query_executed")
+ ),
+ "database_connection_opened": False,
+ "database_session_created": False,
+ "database_write_executed": False,
+ "database_commit_executed": False,
+ "external_network_executed": False,
+ "scheduler_attached": False,
+ "writes_executed": False,
+ "would_write_database": False,
+ "total_rows": postwrite_smoke_result.get("found_count"),
+ "alert_review_state_breakdown": [],
+ "table_statuses": [
+ {
+ "table": "market_alert_review_queue",
+ "exists": bool(row_summaries),
+ "row_count": len(row_summaries),
+ "status": "from_postwrite_smoke_result",
+ }
+ ],
+ }
+
+
+def _build_review_decision_transaction_stack_from_postwrite_evidence(
+ *,
+ service,
+ sample_result,
+ payload_error,
+ operator_evidence,
+ writer_output,
+ postwrite_smoke_result,
+ limit,
+):
+ transaction_preview, handoff = _build_closeout_stack(
+ service=service,
+ sample_result=sample_result,
+ payload_error=payload_error,
+ operator_evidence=operator_evidence,
+ writer_output=writer_output,
+ postwrite_smoke_result=postwrite_smoke_result,
+ limit=limit,
+ )
+ inventory = build_candidate_queue_review_inventory(
+ review_handoff=handoff,
+ postwrite_smoke=postwrite_smoke_result,
+ live_db_inventory=_live_inventory_from_postwrite_smoke(
+ postwrite_smoke_result
+ ),
+ operator_evidence=operator_evidence,
+ execute_requested=False,
+ )
+ decision = build_candidate_queue_review_decision(
+ review_inventory=inventory,
+ operator_evidence=operator_evidence,
+ )
+ approval = build_candidate_queue_review_decision_approval(
+ review_decision=decision,
+ operator_evidence=operator_evidence,
+ )
+ return build_candidate_queue_review_decision_transaction(
+ decision_approval=approval,
+ operator_evidence=operator_evidence,
+ )
+
+
@market_intel_review_bp.route(
"/api/market_intel/manual_sample_review/candidate_queue_review_inventory",
methods=["POST"],
@@ -448,7 +525,7 @@ def market_intel_manual_sample_candidate_queue_review_decision_writer_postwrite_
sample_result, operator_evidence, writer_output, smoke_result, payload_error, limit = (
_extract_run_payload()
)
- transaction = _build_review_decision_transaction_stack(
+ transaction = _build_review_decision_transaction_stack_from_postwrite_evidence(
service=service,
sample_result=sample_result,
payload_error=payload_error,
@@ -456,7 +533,6 @@ def market_intel_manual_sample_candidate_queue_review_decision_writer_postwrite_
writer_output=writer_output,
postwrite_smoke_result=smoke_result,
limit=limit,
- execute_requested=False,
)
data = build_candidate_queue_review_decision_writer_postwrite_smoke(
transaction_preview=transaction,
@@ -464,3 +540,55 @@ def market_intel_manual_sample_candidate_queue_review_decision_writer_postwrite_
)
data["phase"] = service.phase
return jsonify(data), 400 if payload_error else 200
+
+
+@market_intel_review_bp.route(
+ "/api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_operator_drill",
+ methods=["POST"],
+)
+@login_required
+def market_intel_manual_sample_candidate_queue_review_decision_writer_operator_drill():
+ service = MarketIntelService()
+ sample_result, operator_evidence, writer_output, smoke_result, payload_error, limit = (
+ _extract_run_payload()
+ )
+ transaction = _build_review_decision_transaction_stack_from_postwrite_evidence(
+ service=service,
+ sample_result=sample_result,
+ payload_error=payload_error,
+ operator_evidence=operator_evidence,
+ writer_output=writer_output,
+ postwrite_smoke_result=smoke_result,
+ limit=limit,
+ )
+ writer_status = build_candidate_queue_review_decision_writer_cli_plan(
+ transaction_preview=transaction,
+ operator_evidence=operator_evidence,
+ execute_requested=False,
+ apply_real_write=False,
+ approval_token=None,
+ approval_token_secret=None,
+ backup_verified=False,
+ review_inventory_smoke_passed=False,
+ )
+ writer_preflight = build_candidate_queue_review_decision_writer_preflight(
+ writer_status=writer_status,
+ transaction_preview=transaction,
+ operator_evidence=operator_evidence,
+ execute_requested=False,
+ apply_real_write=False,
+ )
+ postwrite_smoke = build_candidate_queue_review_decision_writer_postwrite_smoke(
+ transaction_preview=transaction,
+ execute_requested=False,
+ )
+ data = build_candidate_queue_review_decision_writer_operator_drill(
+ transaction_preview=transaction,
+ writer_preflight=writer_preflight,
+ writer_status=writer_status,
+ postwrite_smoke=postwrite_smoke,
+ operator_evidence=operator_evidence,
+ )
+ data["phase"] = service.phase
+ return jsonify(data), 400 if payload_error else 200
diff --git a/services/market_intel/candidate_queue_review_decision_writer_operator_drill.py b/services/market_intel/candidate_queue_review_decision_writer_operator_drill.py
new file mode 100644
index 0000000..e671b21
--- /dev/null
+++ b/services/market_intel/candidate_queue_review_decision_writer_operator_drill.py
@@ -0,0 +1,360 @@
+"""候選審核 queue review_state writer operator drill preview。
+
+本模組只組裝人工 CLI 更新 review_state 的操作順序與 gate;
+不讀 approval token、不開 DB connection、不更新 review_state、不 commit、不掛 scheduler。
+"""
+
+from services.market_intel.candidate_queue_review_decision_transaction import (
+ ALLOWED_DECISIONS,
+ TARGET_TABLE,
+)
+
+
+FORBIDDEN_TOKEN_KEYWORDS = (
+ "approval_token",
+ "approval-token",
+ "market_intel_queue_write_approval",
+)
+SAFE_TOKEN_METADATA_KEYS = {
+ "approval_token_present",
+ "approval_token_valid",
+ "approval_token_secret_configured",
+}
+SAFE_APPROVAL_ENV_VAR = "MARKET_INTEL_QUEUE_WRITE_APPROVAL"
+
+
+def _as_dict(value):
+ return value if isinstance(value, dict) else {}
+
+
+def _as_list(value):
+ if value is None:
+ return []
+ if isinstance(value, (list, tuple, set)):
+ return list(value)
+ return [value]
+
+
+def _contains_forbidden_token_key(value):
+ if isinstance(value, dict):
+ for key, nested in value.items():
+ normalized_key = str(key).lower()
+ if normalized_key in SAFE_TOKEN_METADATA_KEYS and isinstance(nested, bool):
+ continue
+ if normalized_key == "approval_env_var" and nested == SAFE_APPROVAL_ENV_VAR:
+ continue
+ if any(token_key in normalized_key for token_key in FORBIDDEN_TOKEN_KEYWORDS):
+ return True
+ if _contains_forbidden_token_key(nested):
+ return True
+ elif isinstance(value, list):
+ return any(_contains_forbidden_token_key(item) for item in value)
+ return False
+
+
+def _statement_summary(transaction_preview):
+ transaction_preview = _as_dict(transaction_preview)
+ statements = [_as_dict(item) for item in _as_list(transaction_preview.get("statements"))]
+ invalid = []
+ updates = []
+ for statement in statements:
+ parameter_preview = _as_dict(statement.get("parameter_preview"))
+ dedupe_key = parameter_preview.get("dedupe_key") or _as_dict(
+ statement.get("lookup")
+ ).get("dedupe_key")
+ current_state = (
+ parameter_preview.get("expected_current_review_state")
+ or statement.get("expected_current_review_state")
+ )
+ next_state = parameter_preview.get("next_review_state") or statement.get(
+ "next_review_state"
+ )
+ updates.append(
+ {
+ "idempotency_key": statement.get("idempotency_key"),
+ "dedupe_key": dedupe_key,
+ "expected_current_review_state": current_state,
+ "next_review_state": next_state,
+ "operation": statement.get("operation"),
+ "statement_type": statement.get("statement_type"),
+ "parameter_payload_hash": statement.get("parameter_payload_hash"),
+ }
+ )
+ if (
+ not dedupe_key
+ or current_state != "needs_review"
+ or next_state not in ALLOWED_DECISIONS
+ or statement.get("operation") != "update"
+ or statement.get("statement_type") != "update_review_state"
+ ):
+ invalid.append(statement.get("idempotency_key") or dedupe_key or "unknown")
+ summary = _as_dict(transaction_preview.get("transaction_preview_summary"))
+ return {
+ "transaction_preview_created": bool(
+ transaction_preview.get("transaction_preview_created")
+ ),
+ "transaction_ready": bool(transaction_preview.get("transaction_ready")),
+ "statement_count": int(summary.get("statement_count") or len(statements)),
+ "invalid_statement_count": len(invalid),
+ "invalid_statement_keys": invalid,
+ "allowed_next_states": list(ALLOWED_DECISIONS),
+ "review_state_updates": updates,
+ "target_table": transaction_preview.get("target_table") or TARGET_TABLE,
+ }
+
+
+def _operator_summary(operator_evidence):
+ operator_evidence = _as_dict(operator_evidence)
+ return {
+ "provided_keys": sorted(operator_evidence.keys()),
+ "operator_confirmed_manual_shell_window": bool(
+ operator_evidence.get("operator_confirmed_manual_shell_window")
+ ),
+ "operator_confirmed_transaction_payload_reviewed": bool(
+ operator_evidence.get("operator_confirmed_transaction_payload_reviewed")
+ ),
+ "operator_confirmed_review_state_update_is_not_api": bool(
+ operator_evidence.get("operator_confirmed_review_state_update_is_not_api")
+ ),
+ "operator_confirmed_post_update_inventory_planned": bool(
+ operator_evidence.get("operator_confirmed_post_update_inventory_planned")
+ ),
+ "operator_confirmed_no_api_db_write": bool(
+ operator_evidence.get("operator_confirmed_no_api_db_write")
+ ),
+ "operator_confirmed_no_scheduler_attach": bool(
+ operator_evidence.get("operator_confirmed_no_scheduler_attach")
+ ),
+ "operator_drill_notes_present": bool(
+ str(operator_evidence.get("operator_drill_notes") or "").strip()
+ ),
+ "approval_token_submitted_to_api": _contains_forbidden_token_key(
+ operator_evidence
+ ),
+ }
+
+
+def _gates(statement_summary, operator_summary, writer_preflight, writer_status, postwrite_smoke):
+ return [
+ {
+ "key": "transaction_preview_created",
+ "label": "已產生 review_state transaction preview",
+ "passed": statement_summary["transaction_preview_created"],
+ },
+ {
+ "key": "transaction_ready_for_manual_shell_update",
+ "label": "transaction preview 已通過人工 shell 更新前置 gate",
+ "passed": statement_summary["transaction_ready"],
+ },
+ {
+ "key": "transaction_has_update_statements",
+ "label": "transaction preview 至少有一筆 update_review_state statement",
+ "passed": statement_summary["statement_count"] > 0,
+ },
+ {
+ "key": "transaction_statements_valid",
+ "label": "statement 只能把 needs_review 更新為 confirmed / rejected / deferred",
+ "passed": bool(
+ statement_summary["statement_count"]
+ and statement_summary["invalid_statement_count"] == 0
+ ),
+ },
+ {
+ "key": "writer_preflight_available",
+ "label": "writer preflight 已可用,正式操作前需人工跑只讀檢查",
+ "passed": bool(writer_preflight),
+ },
+ {
+ "key": "writer_cli_gate_available",
+ "label": "review_state writer CLI gate 已可用,真更新只允許 CLI 執行",
+ "passed": bool(writer_status),
+ },
+ {
+ "key": "postwrite_smoke_available",
+ "label": "post-write smoke 已可用,更新後可只讀驗證 review_state",
+ "passed": bool(postwrite_smoke),
+ },
+ {
+ "key": "operator_reviewed_transaction_payload",
+ "label": "操作員已人工確認 transaction payload",
+ "passed": operator_summary["operator_confirmed_transaction_payload_reviewed"],
+ },
+ {
+ "key": "manual_shell_window_acknowledged",
+ "label": "操作員確認只能在人工 shell 寫入窗口執行",
+ "passed": operator_summary["operator_confirmed_manual_shell_window"],
+ },
+ {
+ "key": "post_update_inventory_planned",
+ "label": "操作員確認正式更新後會執行只讀 inventory / smoke",
+ "passed": operator_summary["operator_confirmed_post_update_inventory_planned"],
+ },
+ {
+ "key": "operator_confirmed_no_api_db_write_or_scheduler",
+ "label": "操作員確認 API/UI 不寫 DB、不掛 scheduler",
+ "passed": bool(
+ operator_summary["operator_confirmed_no_api_db_write"]
+ and operator_summary["operator_confirmed_no_scheduler_attach"]
+ and operator_summary["operator_confirmed_review_state_update_is_not_api"]
+ ),
+ },
+ {
+ "key": "operator_drill_notes_present",
+ "label": "operator drill 需留下 notes,方便人工稽核",
+ "passed": operator_summary["operator_drill_notes_present"],
+ },
+ {
+ "key": "operator_drill_no_token_submitted_to_api",
+ "label": "operator_evidence 不得包含一次性 approval token key",
+ "passed": not operator_summary["approval_token_submitted_to_api"],
+ },
+ {
+ "key": "api_does_not_execute_write",
+ "label": "API/UI 不讀 token、不替操作員執行 DB 更新",
+ "passed": True,
+ },
+ {
+ "key": "backup_verified_by_operator",
+ "label": "正式更新前操作員必須完成備份並保留備份檔路徑",
+ "passed": False,
+ },
+ ]
+
+
+def build_candidate_queue_review_decision_writer_operator_drill(
+ *,
+ transaction_preview,
+ writer_preflight,
+ writer_status,
+ postwrite_smoke,
+ operator_evidence=None,
+):
+ """建立 review_state writer operator drill preview;不執行 DB 或 CLI。"""
+ statement_summary = _statement_summary(transaction_preview)
+ operator_summary = _operator_summary(operator_evidence)
+ gates = _gates(
+ statement_summary,
+ operator_summary,
+ _as_dict(writer_preflight),
+ _as_dict(writer_status),
+ _as_dict(postwrite_smoke),
+ )
+ blocked_reasons = [gate["key"] for gate in gates if not gate["passed"]]
+ command_sequence = [
+ {
+ "step": 1,
+ "key": "render_review_state_transaction_json",
+ "label": "將已批准的 review_state transaction preview 存成本機 JSON",
+ "command_shape": "write local review-state-transaction.json outside API",
+ "executes_database": False,
+ },
+ {
+ "step": 2,
+ "key": "run_backup",
+ "label": "正式更新前先執行專案備份",
+ "command_shape": "python3 scripts/tools/backup_system.py",
+ "executes_database": False,
+ },
+ {
+ "step": 3,
+ "key": "run_read_only_preflight",
+ "label": "只讀確認 review queue 欄位、dedupe lookup 與 update contract",
+ "command_shape": (
+ "python3 scripts/market_intel_review_decision_writer.py "
+ "--transaction-json review-state-transaction.json --read-only-preflight"
+ ),
+ "executes_database": False,
+ },
+ {
+ "step": 4,
+ "key": "run_cli_review_state_writer",
+ "label": "只在 CLI shell 以一次性 token 執行受控 review_state update",
+ "command_shape": (
+ "MARKET_INTEL_QUEUE_WRITE_APPROVAL=... "
+ "python3 scripts/market_intel_review_decision_writer.py --execute "
+ "--apply-real-write --transaction-json review-state-transaction.json"
+ ),
+ "executes_database": True,
+ },
+ {
+ "step": 5,
+ "key": "run_postwrite_smoke",
+ "label": "更新後用 dedupe key 只讀確認 review_state 是否符合預期",
+ "command_shape": (
+ "POST /api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_postwrite_smoke?execute=true"
+ ),
+ "executes_database": False,
+ },
+ ]
+ return {
+ "mode": "candidate_queue_review_decision_writer_operator_drill_preview",
+ "target_table": TARGET_TABLE,
+ "target_operation": "update_review_state",
+ "operator_drill_ready": bool(
+ statement_summary["transaction_preview_created"]
+ and statement_summary["statement_count"] > 0
+ and statement_summary["invalid_statement_count"] == 0
+ and not operator_summary["approval_token_submitted_to_api"]
+ ),
+ "ready_for_api_review_state_update": False,
+ "ready_for_api_database_write": False,
+ "ready_for_scheduler_attach": False,
+ "api_executes_cli": False,
+ "api_reads_approval_token": False,
+ "api_writes_file": False,
+ "api_writes_database": False,
+ "api_updates_review_state": False,
+ "approval_record_written": False,
+ "decision_record_written": False,
+ "review_state_update_executed": False,
+ "database_connection_opened": False,
+ "database_session_created": False,
+ "explicit_transaction_opened": False,
+ "transaction_opened": False,
+ "transaction_committed": False,
+ "database_write_executed": False,
+ "database_commit_executed": False,
+ "database_rollback_executed": False,
+ "external_network_executed": False,
+ "scheduler_attached": False,
+ "writes_executed": False,
+ "would_write_database": False,
+ "blocked_reasons": blocked_reasons,
+ "statement_summary": statement_summary,
+ "operator_drill_summary": operator_summary,
+ "gates": gates,
+ "command_sequence": command_sequence,
+ "input_summaries": {
+ "writer_preflight_mode": _as_dict(writer_preflight).get("mode"),
+ "writer_status_mode": _as_dict(writer_status).get("mode"),
+ "postwrite_smoke_mode": _as_dict(postwrite_smoke).get("mode"),
+ "postwrite_smoke_execute_requested": bool(
+ _as_dict(postwrite_smoke).get("execute_requested")
+ ),
+ },
+ "rollback_plan": [
+ {
+ "key": "no_write_no_db_rollback_required",
+ "label": "若 drill preview 或任一 gate 阻擋,沒有 DB rollback 需求",
+ },
+ {
+ "key": "review_state_reversal_requires_manual_audit",
+ "label": "若 CLI 真更新後需回退,必須依 dedupe_key 與審核證據人工稽核",
+ },
+ {
+ "key": "disable_market_intel_flags",
+ "label": "異常時維持 MARKET_INTEL_* flags 關閉並回退 momo-app 程式碼",
+ },
+ ],
+ "safe_boundaries": [
+ "do_not_execute_review_state_writer_from_operator_drill_api",
+ "do_not_read_approval_token_from_operator_drill_api",
+ "do_not_open_database_connection_from_review_state_operator_drill",
+ "do_not_update_review_state_from_review_state_operator_drill",
+ "do_not_commit_review_state_operator_drill",
+ "do_not_attach_scheduler_from_review_state_operator_drill",
+ "no_remove_orphans",
+ "no_momo_db_lifecycle_change",
+ ],
+ }
diff --git a/services/market_intel/deployment_readiness.py b/services/market_intel/deployment_readiness.py
index 5442b9d..33fee5e 100644
--- a/services/market_intel/deployment_readiness.py
+++ b/services/market_intel/deployment_readiness.py
@@ -19,10 +19,11 @@ from services.market_intel.candidate_queue_review_decision_transaction import bu
from services.market_intel.candidate_queue_review_decision_writer_cli import build_candidate_queue_review_decision_writer_cli_plan
from services.market_intel.candidate_queue_review_decision_writer_preflight import build_candidate_queue_review_decision_writer_preflight
from services.market_intel.candidate_queue_review_decision_writer_postwrite_smoke import build_candidate_queue_review_decision_writer_postwrite_smoke
+from services.market_intel.candidate_queue_review_decision_writer_operator_drill import build_candidate_queue_review_decision_writer_operator_drill
BLOCKED_RUN_REVIEW_KEYS = ("ready_for_api_database_write", "ready_for_scheduler_attach", "api_executes_cli", "api_reads_approval_token", "api_writes_file", "api_writes_database", "api_updates_review_state", "approval_record_written", "decision_record_written", "review_state_update_executed", "database_connection_opened", "database_session_created", "explicit_transaction_opened", "transaction_opened", "transaction_committed", "database_write_executed", "database_commit_executed", "database_rollback_executed", "scheduler_attached", "writes_executed", "would_write_database")
-PRODUCTION_SMOKE_TARGETS = ("/health", "/market_intel", "/api/market_intel/status", "/api/market_intel/deployment_readiness", "/api/market_intel/schema_smoke", "/api/market_intel/schema_db_probe", "/api/market_intel/platform_seed_db_diff", "/api/market_intel/legacy_source_bridge", "/api/market_intel/mcp_readiness", "/api/market_intel/mcp_tool_contract", "/api/market_intel/mcp_deploy_preflight", "/api/market_intel/mcp_activation_runbook", "/api/market_intel/mcp_fetch_gate", "/api/market_intel/scheduler_plan", "/api/market_intel/manual_sample_plan", "/api/market_intel/manual_sample_acceptance", "/api/market_intel/manual_sample_review", "/api/market_intel/match_review_plan", "/api/market_intel/opportunity_plan", "/api/market_intel/opportunity_scoring_plan", "/api/market_intel/opportunity_evidence_plan", "/api/market_intel/opportunity_alert_plan", "/api/market_intel/migration_apply_drill", "/api/market_intel/migration_catalog_review", "/api/market_intel/migration_live_smoke", "/api/market_intel/live_db_inventory", "/api/market_intel/manual_sample_review/candidate_queue_writer_postwrite_smoke", "/api/market_intel/manual_sample_review/candidate_queue_writer_operator_drill", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_package", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_readiness", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_receipt", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_closeout", "/api/market_intel/manual_sample_review/candidate_queue_review_handoff", "/api/market_intel/manual_sample_review/candidate_queue_review_inventory", "/api/market_intel/manual_sample_review/candidate_queue_review_decision", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_postwrite_smoke", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status")
+PRODUCTION_SMOKE_TARGETS = ("/health", "/market_intel", "/api/market_intel/status", "/api/market_intel/deployment_readiness", "/api/market_intel/schema_smoke", "/api/market_intel/schema_db_probe", "/api/market_intel/platform_seed_db_diff", "/api/market_intel/legacy_source_bridge", "/api/market_intel/mcp_readiness", "/api/market_intel/mcp_tool_contract", "/api/market_intel/mcp_deploy_preflight", "/api/market_intel/mcp_activation_runbook", "/api/market_intel/mcp_fetch_gate", "/api/market_intel/scheduler_plan", "/api/market_intel/manual_sample_plan", "/api/market_intel/manual_sample_acceptance", "/api/market_intel/manual_sample_review", "/api/market_intel/match_review_plan", "/api/market_intel/opportunity_plan", "/api/market_intel/opportunity_scoring_plan", "/api/market_intel/opportunity_evidence_plan", "/api/market_intel/opportunity_alert_plan", "/api/market_intel/migration_apply_drill", "/api/market_intel/migration_catalog_review", "/api/market_intel/migration_live_smoke", "/api/market_intel/live_db_inventory", "/api/market_intel/manual_sample_review/candidate_queue_writer_postwrite_smoke", "/api/market_intel/manual_sample_review/candidate_queue_writer_operator_drill", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_package", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_readiness", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_receipt", "/api/market_intel/manual_sample_review/candidate_queue_writer_run_closeout", "/api/market_intel/manual_sample_review/candidate_queue_review_handoff", "/api/market_intel/manual_sample_review/candidate_queue_review_inventory", "/api/market_intel/manual_sample_review/candidate_queue_review_decision", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_approval", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_transaction", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_preflight", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_postwrite_smoke", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_operator_drill", "/api/market_intel/manual_sample_review/candidate_queue_review_decision_writer_status")
def _run_review_preview_safe(payload, mode):
@@ -126,6 +127,12 @@ def build_deployment_readiness_preview(
transaction_preview=candidate_queue_review_decision_transaction,
execute_requested=False,
)
+ candidate_queue_review_decision_writer_operator_drill = build_candidate_queue_review_decision_writer_operator_drill(
+ transaction_preview=candidate_queue_review_decision_transaction,
+ writer_preflight=candidate_queue_review_decision_writer_preflight,
+ writer_status=candidate_queue_review_decision_writer_status,
+ postwrite_smoke=candidate_queue_review_decision_writer_postwrite_smoke,
+ )
checks = {
"schema_smoke_passed": bool(schema_smoke["passed"]),
"feature_flags_default_safe": bool(
@@ -372,6 +379,10 @@ def build_deployment_readiness_preview(
candidate_queue_review_decision_writer_postwrite_smoke,
"candidate_queue_review_decision_writer_postwrite_smoke_planned",
),
+ "candidate_queue_review_decision_writer_operator_drill_preview_safe": _run_review_preview_safe(
+ candidate_queue_review_decision_writer_operator_drill,
+ "candidate_queue_review_decision_writer_operator_drill_preview",
+ ),
"candidate_queue_review_decision_writer_cli_status_safe": _run_review_preview_safe(
candidate_queue_review_decision_writer_status,
"candidate_queue_review_decision_writer_cli_blocked",
@@ -610,6 +621,7 @@ def build_deployment_readiness_preview(
"candidate_queue_review_decision_transaction": candidate_queue_review_decision_transaction,
"candidate_queue_review_decision_writer_preflight": candidate_queue_review_decision_writer_preflight,
"candidate_queue_review_decision_writer_postwrite_smoke": candidate_queue_review_decision_writer_postwrite_smoke,
+ "candidate_queue_review_decision_writer_operator_drill": candidate_queue_review_decision_writer_operator_drill,
"candidate_queue_review_decision_writer_status": candidate_queue_review_decision_writer_status,
"match_review_plan": match_review_plan,
"opportunity_plan": opportunity_plan,
diff --git a/services/market_intel/phase.py b/services/market_intel/phase.py
index b6c9c54..7edb3ff 100644
--- a/services/market_intel/phase.py
+++ b/services/market_intel/phase.py
@@ -1,3 +1,3 @@
"""市場情報 rollout phase 單一來源。"""
-MARKET_INTEL_PHASE = "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+MARKET_INTEL_PHASE = "phase_72_candidate_queue_review_decision_writer_operator_drill"
diff --git a/templates/market_intel/disabled.html b/templates/market_intel/disabled.html
index 26fdf2e..f847e85 100644
--- a/templates/market_intel/disabled.html
+++ b/templates/market_intel/disabled.html
@@ -649,6 +649,9 @@
+
@@ -996,6 +999,7 @@
const sampleCandidateQueueReviewDecisionTransaction = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-transaction]') : null;
const sampleCandidateQueueReviewDecisionPreflight = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-preflight]') : null;
const sampleCandidateQueueReviewDecisionPostwriteSmoke = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-postwrite-smoke]') : null;
+ const sampleCandidateQueueReviewDecisionOperatorDrill = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-operator-drill]') : null;
const sampleCandidateQueueReviewDecisionWriter = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-decision-writer]') : null;
const sampleReviewEndpoint = "{{ url_for('market_intel.market_intel_manual_sample_review') }}";
const sampleReviewEvaluateEndpoint = "{{ url_for('market_intel.market_intel_manual_sample_review_evaluate') }}";
@@ -1018,6 +1022,7 @@
const sampleCandidateQueueReviewDecisionTransactionEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_transaction') }}";
const sampleCandidateQueueReviewDecisionPreflightEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_preflight') }}";
const sampleCandidateQueueReviewDecisionPostwriteSmokeEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_postwrite_smoke') }}";
+ const sampleCandidateQueueReviewDecisionOperatorDrillEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_operator_drill') }}";
const sampleCandidateQueueReviewDecisionWriterEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_status') }}";
const schedulerMeta = schedulerRoot ? schedulerRoot.querySelector('[data-market-intel-scheduler-meta]') : null;
const schedulerBody = schedulerRoot ? schedulerRoot.querySelector('[data-market-intel-scheduler-body]') : null;
@@ -3854,6 +3859,113 @@
}
};
+ const renderCandidateQueueReviewDecisionOperatorDrill = data => {
+ const blockers = (data.blocked_reasons || []).join(' / ');
+ const gates = data.gates || [];
+ const commands = data.command_sequence || [];
+ sampleReviewMeta.innerHTML = [
+ `mode=${data.mode || 'unknown'}`,
+ `ready=${data.operator_drill_ready ? 'yes' : 'no'}`,
+ `statements=${(data.statement_summary || {}).statement_count || 0}`,
+ `api_write=${data.api_updates_review_state ? 'yes' : 'no'}`
+ ].map(item => `${escapeHtml(item)}`).join('');
+ sampleReviewBody.innerHTML = `
+
此卡只整理 review_state writer 的人工操作 drill;API/UI 不讀 token、不執行 CLI、不更新 review_state。${blockers ? `阻擋:${escapeHtml(blockers)}` : ''}
+
+
+
OPERATOR GATES
+
${
+ gates.map(gate => `
+
+
+ ${escapeHtml(gate.key)}
+ ${escapeHtml(gate.label)}
+
+
${gate.passed ? 'PASS' : 'BLOCK'}
+
+ `).join('') || '
尚未產生 drill gate。
'
+ }
+
+
+
COMMAND ORDER
+
${
+ commands.map(command => `
+
+
+ ${escapeHtml(`${command.step}. ${command.key}`)}
+ ${escapeHtml(command.command_shape || '')}
+
+
${command.executes_database ? 'DB' : 'NO DB'}
+
+ `).join('') || '
尚未產生命令順序。
'
+ }
+
+
+
+
+
INPUTS
+
${
+ Object.entries(data.input_summaries || {}).map(([key, value]) => `
+
+
${escapeHtml(key)}
+
${escapeHtml(String(value))}
+
+ `).join('') || '
尚未提供輸入摘要。
'
+ }
+
+
+
WRITE FLAGS
+
+ ${[
+ ['api_executes_cli', data.api_executes_cli],
+ ['api_reads_token', data.api_reads_approval_token],
+ ['api_updates_review_state', data.api_updates_review_state],
+ ['review_state_update_executed', data.review_state_update_executed],
+ ['database_write', data.database_write_executed],
+ ['scheduler', data.scheduler_attached]
+ ].map(([key, value]) => `
+
+
${escapeHtml(key)}
+
${escapeHtml(String(value))}
+
+ `).join('')}
+
+
+
+ `;
+ };
+
+ const loadCandidateQueueReviewDecisionOperatorDrill = async () => {
+ if (!sampleReviewMeta || !sampleReviewBody || !sampleReviewInput) return;
+ let parsed;
+ try {
+ parsed = JSON.parse(sampleReviewInput.value || '{}');
+ } catch (error) {
+ sampleReviewMeta.innerHTML = 'json_error';
+ sampleReviewBody.innerHTML = `JSON 格式錯誤:${escapeHtml(error.message)}
`;
+ return;
+ }
+ const body = parsed && parsed.sample_result ? parsed : { sample_result: parsed };
+ sampleReviewBody.innerHTML = '產生 queue review decision writer operator drill 中...
';
+ try {
+ const response = await fetch(sampleCandidateQueueReviewDecisionOperatorDrillEndpoint, {
+ method: 'POST',
+ credentials: 'same-origin',
+ headers: {
+ 'Content-Type': 'application/json',
+ 'X-CSRFToken': csrfToken
+ },
+ body: JSON.stringify(body)
+ });
+ const data = await response.json();
+ if (!response.ok && !data.mode) throw new Error(`HTTP ${response.status}`);
+ renderCandidateQueueReviewDecisionOperatorDrill(data);
+ } catch (error) {
+ sampleReviewMeta.innerHTML = 'error';
+ sampleReviewBody.innerHTML = `queue review decision writer operator drill 失敗:${escapeHtml(error.message)}
`;
+ }
+ };
+
const renderCandidateQueueReviewDecisionWriter = data => {
const blockers = (data.blocked_reasons || []).join(' / ');
const summary = data.statement_summary || {};
@@ -5518,6 +5630,9 @@
if (sampleCandidateQueueReviewDecisionPostwriteSmoke) {
sampleCandidateQueueReviewDecisionPostwriteSmoke.addEventListener('click', loadCandidateQueueReviewDecisionPostwriteSmoke);
}
+ if (sampleCandidateQueueReviewDecisionOperatorDrill) {
+ sampleCandidateQueueReviewDecisionOperatorDrill.addEventListener('click', loadCandidateQueueReviewDecisionOperatorDrill);
+ }
if (sampleCandidateQueueReviewDecisionWriter) {
sampleCandidateQueueReviewDecisionWriter.addEventListener('click', loadCandidateQueueReviewDecisionWriter);
}
diff --git a/tests/test_market_intel_skeleton.py b/tests/test_market_intel_skeleton.py
index 6bea8f1..bdc51be 100644
--- a/tests/test_market_intel_skeleton.py
+++ b/tests/test_market_intel_skeleton.py
@@ -844,6 +844,10 @@ def test_market_intel_preview_template_uses_safe_fetch_false_endpoint():
"market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_postwrite_smoke"
in template
)
+ assert (
+ "market_intel_review.market_intel_manual_sample_candidate_queue_review_decision_writer_operator_drill"
+ in template
+ )
assert (
"data-market-intel-sample-candidate-queue-review-decision-writer"
in template
@@ -856,6 +860,10 @@ def test_market_intel_preview_template_uses_safe_fetch_false_endpoint():
"data-market-intel-sample-candidate-queue-review-decision-postwrite-smoke"
in template
)
+ assert (
+ "data-market-intel-sample-candidate-queue-review-decision-operator-drill"
+ in template
+ )
assert "X-CSRFToken" in template
assert "market_intel.market_intel_scheduler_plan" in template
assert "market_intel.market_intel_match_review_plan" in template
@@ -892,7 +900,7 @@ def test_legacy_source_bridge_default_is_planned_only():
bridge = MarketIntelService().build_legacy_source_bridge()
assert bridge["mode"] == "legacy_source_bridge_planned"
- assert bridge["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert bridge["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert bridge["execute_requested"] is False
assert bridge["read_only_query_executed"] is False
assert bridge["database_connection_opened"] is False
@@ -1050,7 +1058,7 @@ def test_mcp_tool_contract_preview_is_read_only_and_whitelisted():
contract = MarketIntelService().build_mcp_tool_contract()
assert contract["mode"] == "mcp_tool_contract_preview"
- assert contract["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert contract["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert contract["caller"] == "market_intel"
assert contract["contract_ready"] is True
assert contract["blocked_reasons"] == []
@@ -1183,7 +1191,7 @@ def test_mcp_activation_runbook_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "mcp_activation_runbook_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["deployment_actions_executed"] is False
assert data["docker_command_executed"] is False
assert data["ssh_command_executed"] is False
@@ -1196,7 +1204,7 @@ def test_mcp_fetch_gate_default_blocks_external_fetch():
gate = MarketIntelService().build_mcp_fetch_gate(fetch_requested=True)
assert gate["mode"] == "mcp_fetch_gate_planned"
- assert gate["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert gate["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert gate["fetch_requested"] is True
assert gate["manual_fetch_gate_open"] is False
assert gate["network_request_allowed"] is False
@@ -1266,7 +1274,7 @@ def test_mcp_fetch_gate_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "mcp_fetch_gate_planned"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["fetch_requested"] is False
assert data["network_request_allowed"] is False
assert data["external_network_executed"] is False
@@ -1278,7 +1286,7 @@ def test_manual_sample_plan_preview_blocks_fetch_and_write():
plan = MarketIntelService().build_manual_sample_plan()
assert plan["mode"] == "manual_sample_fetch_plan_preview"
- assert plan["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert plan["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert plan["ready_for_manual_sample_fetch"] is False
assert plan["sample_fetch_executed"] is False
assert plan["external_network_executed"] is False
@@ -1326,7 +1334,7 @@ def test_manual_sample_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "manual_sample_fetch_plan_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["sample_fetch_executed"] is False
assert data["external_network_executed"] is False
assert data["database_write_executed"] is False
@@ -1337,7 +1345,7 @@ def test_manual_sample_acceptance_preview_blocks_candidate_import():
acceptance = MarketIntelService().build_manual_sample_acceptance()
assert acceptance["mode"] == "manual_sample_acceptance_preview"
- assert acceptance["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert acceptance["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert acceptance["contract_ready"] is True
assert acceptance["sample_result_loaded"] is False
assert acceptance["sample_result_accepted"] is False
@@ -1379,7 +1387,7 @@ def test_manual_sample_acceptance_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "manual_sample_acceptance_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["sample_result_loaded"] is False
assert data["candidate_import_allowed"] is False
assert data["external_network_executed"] is False
@@ -1391,7 +1399,7 @@ def test_manual_sample_review_preview_is_planned_until_result_loaded():
review = MarketIntelService().build_manual_sample_review()
assert review["mode"] == "manual_sample_review_preview"
- assert review["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert review["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert review["contract_ready"] is True
assert review["sample_result_loaded"] is False
assert review["sample_result_reviewed"] is False
@@ -1502,7 +1510,7 @@ def test_manual_sample_review_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "manual_sample_review_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["sample_result_loaded"] is False
assert data["sample_result_reviewed"] is False
assert data["candidate_import_allowed"] is False
@@ -1541,7 +1549,7 @@ def test_manual_sample_review_evaluation_preview_accepts_payload_without_persist
)
assert review["mode"] == "manual_sample_review_evaluation_preview"
- assert review["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert review["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert review["review_request_type"] == "operator_posted_json"
assert review["payload_received"] is True
assert review["payload_valid_json_object"] is True
@@ -1603,7 +1611,7 @@ def test_manual_sample_review_evaluate_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "manual_sample_review_evaluation_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["payload_received"] is True
assert data["payload_valid_json_object"] is True
assert data["payload_persisted"] is False
@@ -1683,7 +1691,7 @@ def test_manual_sample_candidate_handoff_preview_creates_candidates_without_pers
)
assert handoff["mode"] == "manual_sample_candidate_handoff_preview"
- assert handoff["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert handoff["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert handoff["payload_received"] is True
assert handoff["payload_valid_json_object"] is True
assert handoff["payload_persisted"] is False
@@ -1747,7 +1755,7 @@ def test_manual_sample_candidate_handoff_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "manual_sample_candidate_handoff_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["payload_received"] is True
assert data["handoff_ready"] is True
assert data["candidate_handoff_created"] is True
@@ -1806,7 +1814,7 @@ def test_manual_sample_candidate_queue_draft_preview_builds_review_items_without
)
assert queue_draft["mode"] == "manual_sample_candidate_queue_draft_preview"
- assert queue_draft["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert queue_draft["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert queue_draft["payload_received"] is True
assert queue_draft["payload_valid_json_object"] is True
assert queue_draft["payload_persisted"] is False
@@ -1880,7 +1888,7 @@ def test_manual_sample_candidate_queue_draft_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "manual_sample_candidate_queue_draft_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["payload_received"] is True
assert data["handoff_ready"] is True
assert data["queue_draft_ready"] is True
@@ -1943,7 +1951,7 @@ def test_manual_sample_candidate_queue_approval_preview_blocks_write_and_maps_ro
)
assert approval["mode"] == "manual_sample_candidate_queue_approval_preview"
- assert approval["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert approval["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert approval["payload_received"] is True
assert approval["payload_valid_json_object"] is True
assert approval["payload_persisted"] is False
@@ -2021,7 +2029,7 @@ def test_manual_sample_candidate_queue_approval_route_is_post_only_and_no_write(
assert response.status_code == 200
assert data["mode"] == "manual_sample_candidate_queue_approval_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["payload_received"] is True
assert data["approval_preview_created"] is True
assert data["approval_request_created"] is False
@@ -2084,7 +2092,7 @@ def test_manual_sample_candidate_queue_transaction_preview_blocks_execution():
)
assert transaction["mode"] == "manual_sample_candidate_queue_transaction_preview"
- assert transaction["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert transaction["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert transaction["payload_received"] is True
assert transaction["payload_valid_json_object"] is True
assert transaction["payload_persisted"] is False
@@ -2164,7 +2172,7 @@ def test_manual_sample_candidate_queue_transaction_route_is_post_only_and_no_wri
assert response.status_code == 200
assert data["mode"] == "manual_sample_candidate_queue_transaction_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["payload_received"] is True
assert data["transaction_preview_created"] is True
assert data["transaction_ready"] is False
@@ -4069,6 +4077,99 @@ def test_candidate_queue_review_decision_writer_postwrite_smoke_is_read_only():
assert TEST_APPROVAL_TOKEN not in payload
+def test_candidate_queue_review_decision_writer_operator_drill_preview_is_safe():
+ from services.market_intel.candidate_queue_review_decision_writer_cli import (
+ build_candidate_queue_review_decision_writer_cli_plan,
+ )
+ from services.market_intel.candidate_queue_review_decision_writer_preflight import (
+ build_candidate_queue_review_decision_writer_preflight,
+ )
+ from services.market_intel.candidate_queue_review_decision_writer_postwrite_smoke import (
+ build_candidate_queue_review_decision_writer_postwrite_smoke,
+ )
+ from services.market_intel.candidate_queue_review_decision_writer_operator_drill import (
+ build_candidate_queue_review_decision_writer_operator_drill,
+ )
+
+ transaction, operator_evidence = _build_ready_review_decision_transaction()
+ operator_evidence = {
+ **operator_evidence,
+ "operator_confirmed_manual_shell_window": True,
+ "operator_confirmed_post_update_inventory_planned": True,
+ "operator_drill_notes": "review_state shell drill reviewed",
+ }
+ writer_status = build_candidate_queue_review_decision_writer_cli_plan(
+ transaction_preview=transaction,
+ operator_evidence=operator_evidence,
+ )
+ preflight = build_candidate_queue_review_decision_writer_preflight(
+ writer_status=writer_status,
+ transaction_preview=transaction,
+ operator_evidence=operator_evidence,
+ )
+ smoke = build_candidate_queue_review_decision_writer_postwrite_smoke(
+ transaction_preview=transaction,
+ execute_requested=False,
+ )
+ drill = build_candidate_queue_review_decision_writer_operator_drill(
+ transaction_preview=transaction,
+ writer_preflight=preflight,
+ writer_status=writer_status,
+ postwrite_smoke=smoke,
+ operator_evidence=operator_evidence,
+ )
+ token_leak = build_candidate_queue_review_decision_writer_operator_drill(
+ transaction_preview=transaction,
+ writer_preflight=preflight,
+ writer_status=writer_status,
+ postwrite_smoke=smoke,
+ operator_evidence={**operator_evidence, "approval_token": TEST_APPROVAL_TOKEN},
+ )
+ payload = json.dumps(drill, ensure_ascii=False, sort_keys=True)
+
+ assert drill["mode"] == (
+ "candidate_queue_review_decision_writer_operator_drill_preview"
+ )
+ assert drill["target_table"] == "market_alert_review_queue"
+ assert drill["target_operation"] == "update_review_state"
+ assert drill["operator_drill_ready"] is True
+ assert drill["ready_for_api_review_state_update"] is False
+ assert drill["ready_for_api_database_write"] is False
+ assert drill["ready_for_scheduler_attach"] is False
+ assert drill["api_executes_cli"] is False
+ assert drill["api_reads_approval_token"] is False
+ assert drill["api_writes_file"] is False
+ assert drill["api_writes_database"] is False
+ assert drill["api_updates_review_state"] is False
+ assert drill["review_state_update_executed"] is False
+ assert drill["database_connection_opened"] is False
+ assert drill["database_session_created"] is False
+ assert drill["transaction_opened"] is False
+ assert drill["transaction_committed"] is False
+ assert drill["database_write_executed"] is False
+ assert drill["database_commit_executed"] is False
+ assert drill["scheduler_attached"] is False
+ assert drill["statement_summary"]["statement_count"] == 1
+ assert drill["statement_summary"]["invalid_statement_count"] == 0
+ assert drill["input_summaries"]["writer_preflight_mode"] == (
+ "candidate_queue_review_decision_writer_preflight_preview"
+ )
+ assert drill["input_summaries"]["postwrite_smoke_mode"] == (
+ "candidate_queue_review_decision_writer_postwrite_smoke_planned"
+ )
+ assert len(drill["command_sequence"]) == 5
+ assert any(item["key"] == "run_cli_review_state_writer" for item in drill["command_sequence"])
+ assert "backup_verified_by_operator" in drill["blocked_reasons"]
+ assert "do_not_update_review_state_from_review_state_operator_drill" in drill[
+ "safe_boundaries"
+ ]
+ assert token_leak["operator_drill_ready"] is False
+ assert "operator_drill_no_token_submitted_to_api" in token_leak[
+ "blocked_reasons"
+ ]
+ assert TEST_APPROVAL_TOKEN not in payload
+
+
def test_candidate_queue_writer_preflight_route_is_post_only_and_no_write():
from routes.market_intel_routes import market_intel_bp
@@ -4111,7 +4212,7 @@ def test_candidate_queue_writer_preflight_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_preflight_planned"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["read_only_query_executed"] is False
assert data["database_connection_opened"] is False
@@ -4168,7 +4269,7 @@ def test_candidate_queue_writer_status_route_never_leaks_approval_token(monkeypa
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_cli_blocked"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is True
assert data["apply_real_write_requested"] is True
assert data["approval_token_present"] is False
@@ -4257,7 +4358,7 @@ def test_candidate_queue_writer_postwrite_smoke_route_is_post_only_and_no_write(
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_postwrite_smoke_planned"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["read_only_query_executed"] is False
assert data["database_connection_opened"] is False
@@ -4311,7 +4412,7 @@ def test_candidate_queue_writer_operator_drill_route_is_post_only_and_no_write()
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_operator_drill_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["operator_drill_ready"] is True
assert data["api_executes_cli"] is False
assert data["api_reads_approval_token"] is False
@@ -4367,7 +4468,7 @@ def test_candidate_queue_writer_run_package_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_package_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["package_ready"] is True
assert data["package_artifact_created"] is False
assert data["api_writes_file"] is False
@@ -4433,7 +4534,7 @@ def test_candidate_queue_writer_run_readiness_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_readiness_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["ready_for_cli_operator_run"] is True
assert data["ready_for_api_database_write"] is False
assert data["api_executes_cli"] is False
@@ -4735,7 +4836,7 @@ def test_candidate_queue_writer_run_receipt_route_accepts_inline_payload_no_writ
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_receipt_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["receipt_passed"] is True
assert data["ready_for_api_database_write"] is False
assert data["ready_for_scheduler_attach"] is False
@@ -4783,7 +4884,7 @@ def test_candidate_queue_writer_run_closeout_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_closeout_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["closeout_passed"] is True
assert data["ready_for_next_manual_phase"] is True
assert data["ready_for_api_database_write"] is False
@@ -4832,7 +4933,7 @@ def test_candidate_queue_review_handoff_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_handoff_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["handoff_ready"] is True
assert data["ready_for_manual_queue_review"] is True
assert data["ready_for_api_database_write"] is False
@@ -4890,7 +4991,7 @@ def test_candidate_queue_review_inventory_route_is_post_only_and_no_write():
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_inventory_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["review_inventory_ready"] is False
assert data["ready_for_human_decision_review"] is False
@@ -4956,7 +5057,7 @@ def test_candidate_queue_review_decision_route_is_post_only_and_no_write():
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_decision_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["decision_ready"] is False
assert data["ready_for_human_decision_record"] is False
assert data["ready_for_api_review_state_update"] is False
@@ -5027,7 +5128,7 @@ def test_candidate_queue_review_decision_approval_route_is_post_only_and_no_writ
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_decision_approval_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["approval_ready"] is False
assert data["ready_for_review_state_transaction_preview"] is False
assert data["ready_for_cli_decision_writer"] is False
@@ -5103,7 +5204,7 @@ def test_candidate_queue_review_decision_transaction_route_is_post_only_and_no_w
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_decision_transaction_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["transaction_preview_created"] is False
assert data["transaction_ready"] is False
assert data["ready_for_manual_shell_update_window"] is False
@@ -5185,7 +5286,7 @@ def test_candidate_queue_review_decision_writer_status_route_is_post_only_and_no
assert get_response.status_code == 405
assert response.status_code == 200
assert data["mode"] == "candidate_queue_review_decision_writer_cli_blocked"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is True
assert data["apply_real_write_requested"] is True
assert data["approval_token_present"] is False
@@ -5271,7 +5372,7 @@ def test_candidate_queue_review_decision_writer_preflight_route_is_post_only_and
assert data["mode"] == (
"candidate_queue_review_decision_writer_preflight_preview"
)
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is True
assert data["apply_real_write_requested"] is True
assert data["read_only_query_executed"] is False
@@ -5354,7 +5455,7 @@ def test_candidate_queue_review_decision_writer_postwrite_smoke_route_is_post_on
assert data["mode"] == (
"candidate_queue_review_decision_writer_postwrite_smoke_planned"
)
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["read_only_query_executed"] is False
assert data["database_connection_opened"] is False
@@ -5379,6 +5480,92 @@ def test_candidate_queue_review_decision_writer_postwrite_smoke_route_is_post_on
]
+def test_candidate_queue_review_decision_writer_operator_drill_route_is_post_only_and_no_write():
+ from routes.market_intel_routes import market_intel_bp
+ from routes.market_intel_review_routes import market_intel_review_bp
+
+ fixture = _build_candidate_queue_writer_receipt_fixture(
+ "sample-batch-review-decision-operator-drill-route"
+ )
+ app = Flask(__name__)
+ app.secret_key = "test-secret"
+ app.register_blueprint(market_intel_bp)
+ app.register_blueprint(market_intel_review_bp)
+ client = app.test_client()
+ with client.session_transaction() as session:
+ session["logged_in"] = True
+
+ get_response = client.get(
+ "/api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_operator_drill"
+ )
+ response = client.post(
+ "/api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_operator_drill",
+ json={
+ "sample_result": fixture["sample_result"],
+ "operator_evidence": {
+ **fixture["operator_evidence"],
+ "closeout_artifact_path": "artifacts/market_intel/closeout.json",
+ "operator_confirmed_queue_review_next": True,
+ "operator_confirmed_no_scheduler_attach": True,
+ "operator_confirmed_no_api_db_write": True,
+ "operator_confirmed_inventory_read_only": True,
+ "reviewer_id": "operator-a",
+ "proposed_review_decision": "confirmed",
+ "decision_notes": "manual review only",
+ "operator_confirmed_manual_decision_only": True,
+ "decision_approval_notes": "cli-only approval gate",
+ "operator_confirmed_decision_payload_reviewed": True,
+ "operator_confirmed_decision_apply_requires_cli": True,
+ "operator_confirmed_review_state_update_is_not_api": True,
+ "decision_transaction_notes": "shell-only transaction preview",
+ "operator_confirmed_transaction_payload_reviewed": True,
+ "operator_confirmed_cli_only_transaction": True,
+ "operator_confirmed_manual_shell_window": True,
+ "operator_confirmed_post_update_inventory_planned": True,
+ "operator_drill_notes": "manual shell drill reviewed",
+ },
+ "writer_output": fixture["writer_output"],
+ "postwrite_smoke_result": fixture["postwrite_smoke_result"],
+ },
+ )
+ data = response.get_json()
+ payload = json.dumps(data, ensure_ascii=False, sort_keys=True)
+
+ assert get_response.status_code == 405
+ assert response.status_code == 200
+ assert data["mode"] == (
+ "candidate_queue_review_decision_writer_operator_drill_preview"
+ )
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
+ assert data["operator_drill_ready"] is False
+ assert data["ready_for_api_review_state_update"] is False
+ assert data["ready_for_api_database_write"] is False
+ assert data["ready_for_scheduler_attach"] is False
+ assert data["api_executes_cli"] is False
+ assert data["api_reads_approval_token"] is False
+ assert data["api_writes_file"] is False
+ assert data["api_writes_database"] is False
+ assert data["api_updates_review_state"] is False
+ assert data["database_connection_opened"] is False
+ assert data["database_write_executed"] is False
+ assert data["database_commit_executed"] is False
+ assert data["review_state_update_executed"] is False
+ assert data["scheduler_attached"] is False
+ assert data["statement_summary"]["statement_count"] == 0
+ assert data["input_summaries"]["writer_status_mode"] == (
+ "candidate_queue_review_decision_writer_cli_blocked"
+ )
+ assert "transaction_preview_created" in data["blocked_reasons"]
+ assert "transaction_has_update_statements" in data["blocked_reasons"]
+ assert "backup_verified_by_operator" in data["blocked_reasons"]
+ assert "do_not_execute_review_state_writer_from_operator_drill_api" in data[
+ "safe_boundaries"
+ ]
+ assert TEST_APPROVAL_TOKEN not in payload
+
+
def test_candidate_queue_writer_run_receipt_route_is_post_only_and_no_write():
from routes.market_intel_routes import market_intel_bp
@@ -5407,7 +5594,7 @@ def test_candidate_queue_writer_run_receipt_route_is_post_only_and_no_write():
assert response.status_code == 200
assert data["mode"] == "candidate_queue_writer_run_receipt_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["receipt_passed"] is True
assert data["ready_for_next_manual_review"] is True
assert data["ready_for_api_database_write"] is False
@@ -5432,7 +5619,7 @@ def test_scheduler_plan_preview_blocks_job_attachment():
plan = MarketIntelService().build_scheduler_plan()
assert plan["mode"] == "scheduler_attach_plan_preview"
- assert plan["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert plan["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert plan["ready_to_attach_scheduler"] is False
assert plan["scheduler_attached"] is False
assert plan["scheduler_registration_executed"] is False
@@ -5470,7 +5657,7 @@ def test_scheduler_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "scheduler_attach_plan_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["scheduler_registration_executed"] is False
assert data["crawler_job_started"] is False
assert data["external_network_executed"] is False
@@ -5481,7 +5668,7 @@ def test_match_review_plan_preview_blocks_auto_confirm():
plan = MarketIntelService().build_match_review_plan()
assert plan["mode"] == "match_review_plan_preview"
- assert plan["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert plan["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert plan["ready_for_review_queue"] is False
assert plan["review_queue_created"] is False
assert plan["auto_match_executed"] is False
@@ -5517,7 +5704,7 @@ def test_match_review_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "match_review_plan_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["review_queue_created"] is False
assert data["auto_confirm_executed"] is False
assert data["external_network_executed"] is False
@@ -5528,7 +5715,7 @@ def test_opportunity_plan_preview_blocks_alerts_and_ai_summary():
plan = MarketIntelService().build_opportunity_plan()
assert plan["mode"] == "opportunity_plan_preview"
- assert plan["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert plan["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert plan["ready_for_opportunity_queue"] is False
assert plan["opportunity_queue_created"] is False
assert plan["threat_alert_dispatched"] is False
@@ -5569,7 +5756,7 @@ def test_opportunity_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "opportunity_plan_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["opportunity_queue_created"] is False
assert data["threat_alert_dispatched"] is False
assert data["ai_summary_generated"] is False
@@ -5580,7 +5767,7 @@ def test_opportunity_scoring_plan_preview_blocks_scoring_and_alerts():
plan = MarketIntelService().build_opportunity_scoring_plan()
assert plan["mode"] == "opportunity_scoring_plan_preview"
- assert plan["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert plan["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert plan["ready_for_scoring_job"] is False
assert plan["scoring_job_created"] is False
assert plan["score_calculation_executed"] is False
@@ -5628,7 +5815,7 @@ def test_opportunity_scoring_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "opportunity_scoring_plan_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["scoring_job_created"] is False
assert data["score_calculation_executed"] is False
assert data["sample_scores_generated"] is False
@@ -5640,7 +5827,7 @@ def test_opportunity_evidence_plan_preview_blocks_queries_and_alerts():
plan = MarketIntelService().build_opportunity_evidence_plan()
assert plan["mode"] == "opportunity_evidence_plan_preview"
- assert plan["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert plan["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert plan["ready_for_evidence_bundle"] is False
assert plan["evidence_bundle_created"] is False
assert plan["evidence_query_executed"] is False
@@ -5686,7 +5873,7 @@ def test_opportunity_evidence_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "opportunity_evidence_plan_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["evidence_bundle_created"] is False
assert data["evidence_query_executed"] is False
assert data["sample_evidence_generated"] is False
@@ -5699,7 +5886,7 @@ def test_opportunity_alert_plan_preview_blocks_dispatch_and_llm_calls():
plan = MarketIntelService().build_opportunity_alert_plan()
assert plan["mode"] == "opportunity_alert_plan_preview"
- assert plan["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert plan["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert plan["ready_for_alert_candidates"] is False
assert plan["alert_candidate_created"] is False
assert plan["alert_queue_created"] is False
@@ -5784,7 +5971,7 @@ def test_opportunity_alert_plan_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "opportunity_alert_plan_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["alert_candidate_created"] is False
assert data["alert_queue_created"] is False
assert data["review_queue_created"] is False
@@ -5862,7 +6049,7 @@ def test_mcp_deploy_preflight_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "mcp_external_deploy_preflight_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["deployment_actions_executed"] is False
assert data["docker_command_executed"] is False
assert data["ssh_command_executed"] is False
@@ -5877,7 +6064,7 @@ def test_mcp_readiness_default_is_planned_only(monkeypatch):
readiness = MarketIntelService().build_mcp_readiness()
assert readiness["mode"] == "mcp_readiness_planned"
- assert readiness["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert readiness["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert readiness["execute_requested"] is False
assert readiness["router_enabled"] is False
assert readiness["external_mcp_complete"] is False
@@ -6335,6 +6522,12 @@ def test_deployment_readiness_reports_app_only_release_gate():
]
is True
)
+ assert (
+ readiness["checks"][
+ "candidate_queue_review_decision_writer_operator_drill_preview_safe"
+ ]
+ is True
+ )
assert (
readiness["checks"][
"candidate_queue_review_decision_writer_cli_status_safe"
@@ -6439,6 +6632,11 @@ def test_deployment_readiness_reports_app_only_release_gate():
"candidate_queue_review_decision_writer_postwrite_smoke"
in readiness["production_smoke_targets"]
)
+ assert (
+ "/api/market_intel/manual_sample_review/"
+ "candidate_queue_review_decision_writer_operator_drill"
+ in readiness["production_smoke_targets"]
+ )
assert (
"/api/market_intel/manual_sample_review/"
"candidate_queue_review_decision_writer_status"
@@ -7328,6 +7526,58 @@ def test_deployment_readiness_reports_app_only_release_gate():
]
is False
)
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"]["mode"]
+ == "candidate_queue_review_decision_writer_operator_drill_preview"
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"][
+ "api_executes_cli"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"][
+ "api_reads_approval_token"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"][
+ "api_updates_review_state"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"][
+ "database_connection_opened"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"][
+ "database_write_executed"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"][
+ "database_commit_executed"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"][
+ "review_state_update_executed"
+ ]
+ is False
+ )
+ assert (
+ readiness["candidate_queue_review_decision_writer_operator_drill"][
+ "scheduler_attached"
+ ]
+ is False
+ )
assert (
readiness["candidate_queue_review_decision_writer_status"]["mode"]
== "candidate_queue_review_decision_writer_cli_blocked"
@@ -7478,7 +7728,7 @@ def test_migration_apply_drill_planned_is_safe_and_manual_only():
drill = MarketIntelService().build_migration_apply_drill()
assert drill["mode"] == "migration_apply_drill_preview"
- assert drill["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert drill["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert drill["execute_requested"] is False
assert drill["schema_state"] == "planned_no_db_probe"
assert drill["drill_ready_for_operator_review"] is True
@@ -7593,7 +7843,7 @@ def test_migration_apply_drill_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "migration_apply_drill_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["migration_executed"] is False
assert data["rollback_executed"] is False
@@ -7605,7 +7855,7 @@ def test_migration_catalog_review_planned_is_safe_and_diagnostic():
review = MarketIntelService().build_migration_catalog_review()
assert review["mode"] == "migration_catalog_review_preview"
- assert review["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert review["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert review["execute_requested"] is False
assert review["catalog_state"] == "planned_no_probe"
assert review["seed_state"] == "planned_no_probe"
@@ -7720,7 +7970,7 @@ def test_migration_catalog_review_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "migration_catalog_review_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["catalog_state"] == "planned_no_probe"
assert data["migration_executed"] is False
@@ -7733,7 +7983,7 @@ def test_migration_live_smoke_planned_is_preview_only():
smoke = MarketIntelService().build_migration_live_smoke()
assert smoke["mode"] == "migration_live_smoke_preview"
- assert smoke["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert smoke["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert smoke["execute_requested"] is False
assert smoke["smoke_result"] == "planned_no_execution"
assert smoke["live_smoke_passed"] is False
@@ -7795,7 +8045,7 @@ def test_migration_live_smoke_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "migration_live_smoke_preview"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["smoke_result"] == "planned_no_execution"
assert data["migration_executed"] is False
@@ -7808,7 +8058,7 @@ def test_live_db_inventory_planned_is_preview_only():
inventory = MarketIntelService().build_live_db_inventory()
assert inventory["mode"] == "live_db_inventory_planned"
- assert inventory["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert inventory["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert inventory["execute_requested"] is False
assert inventory["read_only_query_executed"] is False
assert inventory["database_connection_opened"] is False
@@ -7952,7 +8202,7 @@ def test_live_db_inventory_route_is_preview_only():
assert response.status_code == 200
assert data["mode"] == "live_db_inventory_planned"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["read_only_query_executed"] is False
assert data["database_write_executed"] is False
@@ -8179,7 +8429,7 @@ def test_candidate_queue_writer_cli_script_outputs_blocked_gate(tmp_path):
assert result.returncode == 0
assert data["mode"] == "candidate_queue_writer_cli_blocked"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["apply_real_write_requested"] is False
assert data["writes_executed"] is False
@@ -8208,7 +8458,7 @@ def test_review_decision_writer_cli_script_outputs_blocked_gate_without_login_en
assert result.returncode == 0
assert data["mode"] == "candidate_queue_review_decision_writer_cli_blocked"
- assert data["phase"] == "phase_71_candidate_queue_review_decision_writer_postwrite_smoke"
+ assert data["phase"] == "phase_72_candidate_queue_review_decision_writer_operator_drill"
assert data["execute_requested"] is False
assert data["apply_real_write_requested"] is False
assert data["approval_token_present"] is False