Truthful provenance for an operator-invoked snapshot

The internal one-shot route already called the SAME production runSnapshot with
the SAME default dependencies — but it passed no trigger, and runSnapshot
defaults an absent trigger to SCHEDULED. So every operator-invoked run was
recorded as though the cron had fired it. That was a lie about provenance,
present by omission, and it would have contaminated the trace of any forced
diagnostic run.

CONTROLLED_FORCED is now its own trigger. Both internal routes (`/snapshot/:sport`
and `/snapshot/all`) stamp it, along with the process generation. The scheduler
still stamps SCHEDULED, and a test asserts neither internal route can label
itself scheduled.

Trace retention moves from "scheduled only" to a named allow-list of SCHEDULED +
CONTROLLED_FORCED. INTRADAY is still refused — it runs every ~20 minutes and
would displace scheduled evidence, which is the failure the store exists to
prevent. MANUAL_API stays refused too.

THE PIPELINE IS UNTOUCHED. snapshotService, gradeSlateService, retentionService,
snapshotScheduler, oddsService and eventIdentity are all UNCHANGED. A test
asserts the route injects no dependency override — no getOdds, gradeAndCacheSlate,
retention, ledger, cacheSet/cacheGet, gameBinder, eventIdentity, mlbAdapter or
notify — so the only difference from a scheduled invocation is the label and the
absence of a scheduled hour, which a forced run genuinely does not have.

The ?limit bisect-hook invariant is preserved and tightened: the opts passed
carry exactly {trigger, processStartedAt} and never a stray limit.

Teeth, injections verified present, against a green baseline:
  :sport route mislabelled SCHEDULED -> 3 fail
  /all route mislabelled SCHEDULED   -> 2 fail
  intraday admitted to the store     -> 5 fail
  trigger filter removed             -> 3 fail

THE FIRST TEETH RUN WAS INVALID AND IS DISCARDED: both routes live in one file,
so a single-occurrence replace hit `/snapshot/all` and left `/snapshot/:sport`
correct — the injection landed on the wrong target and the suite passed. Coverage
for `/all` was added, plus a test that the file contains exactly two
CONTROLLED_FORCED stamps and zero SCHEDULED ones, then both were re-run failing
independently.

Four stale assertions updated with the reason recorded: three pinned the
`not_scheduled` refusal string (now trigger-agnostic) and one pinned an empty
opts object on the route.

389 suites / 5,280 tests pass. web tsc exit 0. Lineage stays OFF.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CQJeAG8vcDoL5zkiaJyVb8
This commit is contained in:
Kev
2026-08-28 02:56:22 -04:00
parent c1d9ec5bbb
commit f54b0627e1
6 changed files with 169 additions and 12 deletions
+11 -4
View File
@@ -38,10 +38,17 @@ describe('POST /api/internal/snapshot/:sport', () => {
.set('x-internal-key', 'test-key-123')
.send({});
expect(res.status).toBe(200);
// Opts object added 2026-08-01 for the ?limit= bisect hook. With no
// ?limit the opts must be EMPTY — a stray limit here would silently cap
// production runs, which is the exact bug the hook exists to diagnose.
expect(snapshot.runSnapshot).toHaveBeenCalledWith('mlb', {});
// Opts object added 2026-08-01 for the ?limit= bisect hook. With no ?limit
// there must be NO limit key — a stray one would silently cap production
// runs, which is the exact bug the hook exists to diagnose. The opts now
// also carry truthful provenance (an operator run is CONTROLLED_FORCED, not
// SCHEDULED); those two diagnostic keys are the only permitted additions.
expect(snapshot.runSnapshot).toHaveBeenCalledWith('mlb', expect.objectContaining({
trigger: 'CONTROLLED_FORCED',
}));
const passedOpts = snapshot.runSnapshot.mock.calls[0][1];
expect(Object.keys(passedOpts).sort()).toEqual(['processStartedAt', 'trigger']);
expect(passedOpts).not.toHaveProperty('limit');
expect(res.body.summary.gradeCount).toBe(3);
});