Skip to content

Add Spring Boot expense approvals with optimistic locking - #444

Draft
sdairs wants to merge 2 commits into
mainfrom
codex/expense-approvals
Draft

sdairs wants to merge 2 commits into
mainfrom
codex/expense-approvals

Conversation

@sdairs

@sdairs sdairs commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Employees can draft and submit GBP expenses; managers can approve or reject submitted requests. The API derives ownership from demo bearer-token identities, prevents self-decisions, and requires an expected version on each write. Spring transactions and JPA @Version ensure competing edits or decisions produce one commit and one HTTP 409.

Flyway uses an explicit migration entry point and schema-owner credential. Runtime validates the schema, uses restricted CRUD privileges, and verifies the Cloud CA and hostname. The README shows visible Cloud setup, role/bootstrap/migration/grants/seed steps, HTTP usage and dedicated-service cleanup. CI checks the Java 21 build and domain tests without Cloud credentials.

Validation on 2 October 2026, native Ubuntu VM, Spring Boot 4.1.1 and Postgres 18.6 in ClickHouse Cloud:

  • ./mvnw -B verify: 4 domain tests passed and packaged jar built.
  • Empty schema/roles → bootstrap → 2 Flyway migrations → grants → seed; repeated migration and seed passed without manual grants.
  • ./mvnw -B -Pcloud verify: 5 Cloud tests passed, including a barrier-coordinated JPA race, rollback after flush, runtime permission denials, malformed decision rows, and wrong-CA certificate failure with positive connection control.
  • python3 scripts/acceptance.py: validation/forged-owner rejection, cross-user access, status filtering, role and self-decision checks passed. Three edit/submit and three manager-decision races each returned one 200 and one 409. Production jar restart retained the persisted request and version.

Bounded demo: GBP only, at most 100 visible rows, no pagination, audit events, payments or token-issuance service. Companion article and private evidence remain outside this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant