feat: wave 2 migration (P3, P5, P7 openspec changes)

Implements, verifies, and archives the three remaining Wave 2 changes from
openspec/MIGRATION-PLAN.md.

- add-wallet-settlement (P3): demo recharge, guarded withdrawal freeze and
  one-time admin review, paginated own fund entries, idempotent per-shop
  weekly/monthly settlement statements with commission rate and one-time
  payout confirmation.
- add-merchant-onboarding (P5): personal/enterprise applications with one live
  application per user, guarded review with mandatory rejection reason, and
  transactional shop + owner provisioning returning one-time credentials;
  mall onboarding/status pages and an admin review console.
- add-membership-messaging (P7): platform member levels, append-only growth
  accrual on order completion with guarded one-way leveling, order/shipment/
  refund system messages with unread/read state and soft deletion, plus the
  mall header unread badge.

Backend: migrations 0019-0023, new wallet, settlement, merchant_onboarding,
membership and messaging modules, event hooks in order/fulfillment/aftersale,
and integration suites for each. Shared contract extended and all three
frontends updated; code indexes, domain docs, backend guidelines and the
migration tracker synced.

Verification: cargo test -p vmall-api green twice consecutively; mall, admin
and shop-admin builds pass; browser smoke on every new surface; openspec
validate --all --strict green (33 passed).

The three changes share the @vmall/shared contract, the mall mock adapter and
per-app locale/nav files, so they are committed together to keep every commit
buildable.
This commit is contained in:
2026-09-25 15:25:29 +00:00
parent 772aafa3fb
commit 9904696e76
120 changed files with 14097 additions and 125 deletions
@@ -0,0 +1,27 @@
## ADDED Requirements
### Requirement: Withdrawal review and commission configuration
The platform console SHALL list withdrawal applications and approve or reject each pending application through the shared API contract, surfacing review outcomes and conflicts (409 on a repeated review) without silent failure. It SHALL expose the platform commission rate as an integer basis-point setting that admins can read and update.
#### Scenario: reject returns funds
- **WHEN** an admin rejects a pending withdrawal application
- **THEN** the console shows the rejected status and the buyer's wallet reflects the amount back in available balance
#### Scenario: approve deducts frozen funds
- **WHEN** an admin approves a pending withdrawal application
- **THEN** the console shows the approved status and the frozen balance decreases by the requested amount
#### Scenario: set commission rate
- **WHEN** an admin updates the commission rate
- **THEN** settlement statements generated afterwards snapshot the new rate
### Requirement: Settlement statement confirmation
The platform console SHALL list settlement statements across shops with their amount snapshots and statuses, allow manual generation for a shop and closed period, and confirm payout exactly once per statement through the shared API contract, surfacing a 409 on repeated confirmation.
#### Scenario: confirm payout
- **WHEN** an admin confirms a pending statement
- **THEN** the console shows the statement confirmed and the shop owner's ledger records the payout
#### Scenario: manual generation is idempotent
- **WHEN** an admin generates a statement for a shop and period that already has one
- **THEN** the existing statement is shown and no duplicate is created