WI-069 · Platform & Contracts · platform-foundations-api
queued P1 medium risk Owner: Paul Reviewer: Paul 0% · 0/1 tasks complete
| Code | WI-069 |
|---|---|
| Phase | Platform & Contracts |
| Order | 30 of 93 |
| Story points | 8 |
| Primary surface | Typed app/edge API + public/buyer/seller/internal DTOs |
| Retires | — |
| Depends on | Data authority & RLS foundation (tenants/memberships/roles/permissions/assignments, auth helpers, deny-by-default membership RLS, schema+migration contract, demo parity) |
| Blocks | — |
Give the web/mobile/MCP surfaces one typed contract over the P-gate domain functions, with strict DTO separation so no app route leaks base-table rows.
API envelope
DTO boundary
Invocation (G12)
Invocation = gateway (D33)
P9 Platform Foundations: app/edge API envelope + DTO boundary, ID/idempotency/correlation convention, cross-version compatibility registry, keyless CI floor, and the legacy-route quarantine registry that blocks P&C exit on any contract bypass.No linked requirements.
One typed app/edge API envelope behind a server/edge gateway (D33: Next.js routes / Cloudflare Workers — not direct client→Supabase); public / buyer-private / seller-private / internal DTOs separated; routes consume P6 public-safe views/RPCs (no base-table rows where a projection is required); tenant/actor resolved server-side; service-role server-only. Per P9 spec + D33.
No paid API / infra spend triggered by this item.
queued Sprint: P&C Wave 4: Data & Surfaces
Edit status / sprint on the ★ Live Board → — changes are logged live with who / when / why.
No human tasks linked.
None recorded yet.
None recorded yet.
None recorded yet.
No tool calls recorded.
No files / artifacts recorded.
No log entries yet.