Skip to content

RFC-0002: orchestrate legacy batch processing - #17

Merged
EstandarMustaq merged 2 commits into
rfc-0002-openapi-contractfrom
rfc-0002-legacy-batch-orchestration
Jul 16, 2026
Merged

EstandarMustaq merged 2 commits into
rfc-0002-openapi-contractfrom
rfc-0002-legacy-batch-orchestration

Conversation

@EstandarMustaq

Copy link
Copy Markdown
Contributor

Summary

  • add LEGACY_EXPORT and LEGACY_IMPORT jobs on the legacy queue
  • expose compliance-managed batch request, status, artifact, rejection and delivery APIs
  • integrate the durable legacy-connectors runtime and Ledger Core source
  • add batch metrics, deduplicated jobs and Docker packaging for connector contracts
  • extend the public Workbench OpenAPI contract

Validation

  • pnpm test:all
  • pnpm build
  • pnpm openapi:check
  • pnpm guardian:check
  • git diff --check

Depends on mavulahq/legacy-connectors branch rfc-0002-executable-batch-runtime.

@EstandarMustaq
EstandarMustaq marked this pull request as ready for review July 16, 2026 20:26
@EstandarMustaq
EstandarMustaq merged commit 98c3a56 into rfc-0002-openapi-contract Jul 16, 2026
1 check passed
@EstandarMustaq
EstandarMustaq deleted the rfc-0002-legacy-batch-orchestration branch July 16, 2026 20:27
EstandarMustaq added a commit that referenced this pull request Jul 16, 2026
* feat: publish versioned public api contract

* RFC-0002: orchestrate legacy batch processing (#17)

* feat: orchestrate legacy batch processing

* docs: expand public workbench API contract (#18)
EstandarMustaq added a commit that referenced this pull request Jul 16, 2026
* fix: reject cross-tenant domain jobs

* RFC-0002: publish workbench public API contract (#16)

* feat: publish versioned public api contract

* RFC-0002: orchestrate legacy batch processing (#17)

* feat: orchestrate legacy batch processing

* docs: expand public workbench API contract (#18)
EstandarMustaq added a commit that referenced this pull request Jul 16, 2026
* feat: secure worker runtime with OIDC

* RFC-0002: reject cross-tenant domain jobs (#15)

* fix: reject cross-tenant domain jobs

* RFC-0002: publish workbench public API contract (#16)

* feat: publish versioned public api contract

* RFC-0002: orchestrate legacy batch processing (#17)

* feat: orchestrate legacy batch processing

* docs: expand public workbench API contract (#18)

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5ab034447e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

}

@Get('metrics')
@Public()

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Remove public access from protected metrics endpoint

In deployments where /api/metrics is reachable without a separate auth layer, this new @Public() decorator makes the route bypass both AccessTokenGuard and PermissionsGuard, because those guards return early for PUBLIC_ROUTE before checking the bearer token or observability.read. That leaves the permission annotation on the next line ineffective and exposes worker/queue/batch operational metrics to unauthenticated callers; drop @Public() unless metrics scraping is intentionally unauthenticated at this service boundary.

Useful? React with 👍 / 👎.


private async enqueue(batchId: string, tenantId: string, type: 'LEGACY_EXPORT' | 'LEGACY_IMPORT'): Promise<void> {
await this.jobs.enqueue({
job_id: `legacy-${batchId}`, queue: 'legacy', type, tenant_id: tenantId,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Ensure the legacy queue is actually consumed

When an installation already sets WORKBENCH_QUEUES/FWK_QUEUES to the old payments,platform value, this still writes batch work to the hard-coded legacy queue, but WorkerService only creates workers for config.queues and never consumes queues outside that list. In that context regulatory exports/imports return QUEUED and remain stuck indefinitely; validate/force-add legacy for these endpoints or enqueue to a configured queue.

Useful? React with 👍 / 👎.

Comment thread src/types.ts
Comment on lines +14 to +15
'LEGACY_EXPORT',
'LEGACY_IMPORT',

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep internal legacy jobs out of the public job API

Adding these internal batch job types to the shared JOB_TYPES list also makes /api/jobs accept them, because JobsController.validateCreateJob authorizes any value in this list with only workbench.jobs.write. In tenants where a job writer knows a batch id, they can enqueue LEGACY_EXPORT/LEGACY_IMPORT on the legacy queue and drive compliance batch processing without the compliance.manage permission required by the new legacy endpoints; use a separate allowlist for public job submissions or keep these types internal.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant