Lay the cross-cutting platform backbone every later phase reads from. Adds
the first marketplace EF migration baseline (new `ops` schema) and the
mechanisms b2..b15 reuse: typed runtime config, an append-only audit trail,
an analytics event log, the holiday/bank-closure calendar, in-app
notifications, and the internal support-alert worklist.
Schema & migration
- New `ops` schema + migration InitialMarketplaceBaseline with 6 tables:
PlatformConfigs (IAuditable), AuditLogs (append-only), SystemEvents,
IranianHolidays, Notifications, SupportAlerts — with indexes/uniques and
FKs to usr.Users. Seeded 12 config keys + 7 sample holidays via HasData.
Domain / Application
- IAuditable marker + [AuditRedacted] attribute; entities + string-code
constant holders (config data_type, holiday type, alert type/severity/status).
- Facade contracts: IPlatformConfig, IHolidayCalendar, IAnalyticsSink,
IAuditLogger, INotificationService, ISupportAlertService; DTOs +
PagedResult<T>; evolved the INotificationDispatcher.Notification record to
carry Type + DataJson; Pagination helper.
- 14 CQRS commands/queries (+ validators) wiring the endpoints to the facades.
Infrastructure
- DB-backed facade implementations in Persistence/Services/; real in-app
INotificationDispatcher (removes the b0 log stub); notification-retention
hosted service (purge is_read=1 AND age>90d).
- Extended AuditFieldInterceptor to also append an old/new-diff audit_logs row
for every IAuditable change in the same transaction (PII redacted).
- Registered all facades + hosted service in AddPersistenceServices; removed
the dispatcher registration from AddCrossCuttingSeams.
API
- 5 controllers: admin PlatformConfig/Holidays/Audit/SupportAlerts
([Authorize(DynamicPermission)]) + current-user Notifications ([Authorize]),
all tenant-scoped and paginated. 16 Swagger paths total.
Money-correctness & safety rules honoured
- Config read at compute time (cached, parsed by data_type), never hardcoded;
every config change is audited in the same transaction; audit_logs is
append-only (no update/delete path); support alerts are admin-only;
notifications are tenant-scoped; analytics is fire-and-forget.
Tests & docs
- 18 new foundation tests over in-memory SQLite (config typing + audit,
holidays, notifications + tenancy + retention, support alerts, analytics);
build clean (0 new code warnings), 22 tests green; migration applied to the
dev DB and swagger.v1.json refreshed.
- Updated server Project map + CONVENTIONS, product data-model doc 12 (seeded
config defaults), config-reference contract, mock registry, backend handoff/
STATUS/report.
Follow-ups: add FK constraints for SupportAlerts.BookingId (b9) and ReviewId
(b14) when those tables land.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Remove the Order demo (entity/feature/repo/config/gRPC/proto) and the three
pre-marketplace migrations; regenerate a fresh InitialBaseline migration.
Stand up the REST surface (PingController + System/Ping CQRS) proving the
Mediator -> behaviors -> OperationResult -> ApiResult envelope end to end.
Close wiring gaps: register LoggingBehavior (outermost) and add the built-in
rate limiter (per-IP global + otp/auth/sensitive policies), placed before
authentication.
Add current-user + audit plumbing: ICurrentUser (HttpContext + null impls),
rename BaseEntity audit fields to CreatedAt/ModifiedAt (DateTimeOffset) +
CreatedById/ModifiedById, stamped by a new AuditFieldInterceptor.
Introduce five cross-cutting seams (IDateTimeProvider, IFieldEncryptor,
ICacheService, IObjectStorage, INotificationDispatcher) with in-memory/local
mocks registered via AddCrossCuttingSeams.
Add Baya.Test.Foundation (encryptor, audit interceptor, ping handler) and
update docs, contracts (swagger.v1.json), handoff, report, and mocks registry.