You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Configurable Worker sales allocation scope by flock assignment #612
Discovered during #388 / PR #611 review. #388 scopes a restricted Worker's reads to assigned flocks, but Workers are also intentionally allowed to create and confirm sales (AuthPolicies.SalesFlow, #73 principle). Sale confirmation allocates egg lots FIFO without asking the operator to choose a flock.
PR #611 briefly applied flock scope to EggLotRepository.GetAvailableFifoLockedAsync, which would make a restricted Worker see false EggLot.InsufficientStock whenever assigned-flock stock is insufficient even though the farm has enough stock elsewhere. #388 will preserve current main behavior (farm-wide FIFO allocation) and defer configurable sales allocation to this issue.
Owner decisions (2026-08-27)
Add a persisted farm setting controlling plain-Worker sale allocation:
AssignedFlocksOnly — default.
AllFarmFlocks — opt-in.
Owner and Manager may change it in Farm Settings.
The setting applies only to plain Workers. Owner, Manager, and Sales-role users always retain farm-wide FIFO allocation.
A Worker whose assigned-flock stock cannot fulfill the order must receive a specific warning when farm-wide stock could fulfill it: explain that an Owner/Manager can allow selling from other flocks.
Trigger that warning for any assigned-stock shortfall, not only zero assigned stock.
If farm-wide stock is also insufficient, keep the normal insufficient-stock error.
Required behavior
Allocation decision
At confirm time, derive effective allocation scope from both the actor and the farm setting:
Actor
Farm setting
FIFO candidate lots
Owner / Manager / Sales
either
all account/farm lots
Plain Worker with zero assignment rows or a farm-wide assignment row
either
all account/farm lots (existing unrestricted semantics)
Restricted plain Worker
AssignedFlocksOnly
assigned flocks only
Restricted plain Worker
AllFarmFlocks
all account/farm lots
Do not infer role from the setting or from assignment presence. Use the same effective-role semantics as AuthPolicies/CurrentUserContext.
Insufficient assigned stock discriminator
For AssignedFlocksOnly, if scoped FIFO cannot fulfill a line:
Determine whether the same line/order could be fulfilled by farm-wide eligible stock under the same date, grade, quantity-available, and withdrawal rules.
If yes, return a distinct stable error code (name during design) whose user-facing message says the Worker is limited to assigned-flock stock and an Owner/Manager can enable cross-flock selling in Farm Settings.
If no, return existing EggLot.InsufficientStock.
The probe must not allocate, mutate, or change lock ordering. Design the concurrency/lock semantics explicitly; do not issue an unlocked preflight that can make a promise the locked allocation immediately contradicts.
Settings surface
Add the setting to Account farm settings and bump Version when changed.
Context
Discovered during #388 / PR #611 review. #388 scopes a restricted Worker's reads to assigned flocks, but Workers are also intentionally allowed to create and confirm sales (
AuthPolicies.SalesFlow, #73 principle). Sale confirmation allocates egg lots FIFO without asking the operator to choose a flock.PR #611 briefly applied flock scope to
EggLotRepository.GetAvailableFifoLockedAsync, which would make a restricted Worker see falseEggLot.InsufficientStockwhenever assigned-flock stock is insufficient even though the farm has enough stock elsewhere. #388 will preserve currentmainbehavior (farm-wide FIFO allocation) and defer configurable sales allocation to this issue.Owner decisions (2026-08-27)
AssignedFlocksOnly— default.AllFarmFlocks— opt-in.Required behavior
Allocation decision
At confirm time, derive effective allocation scope from both the actor and the farm setting:
AssignedFlocksOnlyAllFarmFlocksDo not infer role from the setting or from assignment presence. Use the same effective-role semantics as
AuthPolicies/CurrentUserContext.Insufficient assigned stock discriminator
For
AssignedFlocksOnly, if scoped FIFO cannot fulfill a line:EggLot.InsufficientStock.Settings surface
Accountfarm settings and bumpVersionwhen changed.InitialCreateremains frozen (feat(eggs): make cracked and dirty eggs sellable stock via condition grades (#396) #407).specs/product/GLOSSARY.md, SPA Help/in-app glossary, and all supported locales (en/es/tl).Acceptance criteria
AssignedFlocksOnly.AllFarmFlocksallocates across all farm flocks.EggLot.InsufficientStock.docs/schema/regenerated and checked.Non-goals
FlockScopeGuardbehavior for production recording.