Integrate Double-Export Guard with Exporter Pipeline
epic-accounting-system-export-engine-task-007 — Wire the Double-Export Guard into the exporter execution pipeline. Before any exporter runs, invoke the guard to obtain the filtered approved-claims batch. After successful export payload generation, call the guard's mark operation to record the export run reference on all included claims. Handle failure cases: if marking fails after successful payload generation, surface an error without losing the export artifact.
Acceptance Criteria
Technical Requirements
Execution Context
Tier 3 - 413 tasks
Can start after Tier 2 completes
Implementation Notes
Implement the pipeline as a use-case class (e.g., RunExportPipelineUseCase) that accepts an AccountingExporter and DoubleExportGuard as constructor-injected dependencies — this keeps the pipeline testable without real exporters. The sequence is strictly: (1) guard.filterBatch() → (2) if empty, return ExportResult.empty; (3) exporter.generatePayload(batch) → (4) on payload success: exportRunRepo.create(runRef) → (5) guard.markExported(claimIds, runRef) → (6) on mark failure: return ExportResult.markFailed(artifact: payload). Use a sealed class for ExportResult to force callers to handle all outcomes. Never swallow the payload on mark failure — store it in a recoverable artifact location (e.g., Supabase Storage temp bucket) so an admin can retry the mark without re-generating.
Avoid placing the mark logic in the exporter itself; keep exporters pure payload generators.
Testing Requirements
Unit tests using flutter_test with mocked DoubleExportGuard and ExportRunRepository. Integration tests against a local Supabase instance covering: (1) guard returns filtered batch correctly, (2) mark succeeds after payload generation, (3) mark failure preserves artifact and surfaces error, (4) empty batch terminates gracefully. Use fake_async for time-sensitive concurrency checks. Minimum 90% branch coverage on the pipeline integration code.
The Xledger CSV/JSON import specification may not be available in full detail at implementation time. If the field format, column ordering, encoding requirements, or required fields differ from assumptions, the generated file will be rejected by Xledger on first production use.
Mitigation & Contingency
Mitigation: Obtain the official Xledger import specification document from Blindeforbundet before starting XledgerExporter implementation. Build a dedicated acceptance test that validates a sample export file against all documented constraints.
Contingency: If the spec arrives late, implement a configurable column-mapping layer so that field order and names can be adjusted via configuration without code changes. Ship a file-based export that coordinators can manually verify before connecting to Xledger import.
The atomic claim-marking transaction in Double-Export Guard could fail under high concurrency if two coordinators trigger an export for overlapping date ranges simultaneously, potentially allowing duplicate exports to proceed past the guard.
Mitigation & Contingency
Mitigation: Use a database-level advisory lock or a SELECT FOR UPDATE on the relevant claim rows within the export transaction to serialize concurrent exports per organization. Add an integration test that simulates concurrent export triggers.
Contingency: If locking proves problematic at the database level, implement an application-level distributed lock using a Supabase row in a dedicated export_locks table with an expiry timestamp and automatic cleanup on failure.
HLF's Dynamics portal API endpoint may not be available or documented in time for Phase 1, leaving DynamicsExporter unable to be validated against a real system and potentially shipping with an incorrect field schema.
Mitigation & Contingency
Mitigation: Design DynamicsExporter for file-based export first (CSV/JSON download), with the API push implemented behind a feature flag. Request a Dynamics test environment or sandbox from HLF as early as possible.
Contingency: Ship DynamicsExporter as a file export only for Phase 1. Phase the API push integration into a follow-on task once the Dynamics sandbox is available, using the same AccountingExporter interface with no breaking changes.