docs: integrate gap analysis constraints into architecture and roadmap specifications

This commit is contained in:
Luis Gabriel Ramos Robles 2026-06-11 13:48:34 +00:00
parent fea880fadc
commit a7dbc00bfc
2 changed files with 52 additions and 25 deletions

View file

@ -134,6 +134,8 @@ erDiagram
decimal amount decimal amount
int sales_count int sales_count
string status "PENDING | PROCESSED" string status "PENDING | PROCESSED"
string idempotency_key UK
string transaction_id
int uploaded_by FK int uploaded_by FK
datetime created_at datetime created_at
} }
@ -141,18 +143,21 @@ erDiagram
SETTLEMENTS { SETTLEMENTS {
int id PK int id PK
string period "YYYY-MM" string period "YYYY-MM"
int plan_id FK int plan_id FK "References specific version of the plan"
int user_id FK int user_id FK
decimal sales_amount decimal sales_amount
decimal goal_amount decimal goal_amount
decimal achievement_percentage decimal achievement_percentage
decimal calculated_commission decimal calculated_commission
decimal calculated_bonus decimal calculated_bonus
decimal total_payout decimal adjustment_amount "Clawback or adjustment delta"
decimal total_payout "calculated_commission + calculated_bonus + adjustment_amount"
string status "SIMULATED | PENDING | APPROVED | REJECTED" string status "SIMULATED | PENDING | APPROVED | REJECTED"
int approved_by FK int approved_by FK
datetime approved_at datetime approved_at
string rejection_reason string rejection_reason
int original_settlement_id FK "Self-references the settlement adjusted, if any"
string adjustment_notes
datetime created_at datetime created_at
} }
@ -229,6 +234,18 @@ We define role-based access restrictions as follows:
| **Consulta** | Read-only. | No mutations allowed. | | **Consulta** | Read-only. | No mutations allowed. |
| **Colaborador** | Consults own history & dashboard. | Restricted to `user_id`. | | **Colaborador** | Consults own history & dashboard. | Restricted to `user_id`. |
### 5.1. PostgreSQL Row-Level Security (RLS) & Data Isolation
To ensure absolute segregation of sensitive compensation data, the database implements **Row-Level Security (RLS)**. RLS is enforced at the database layer (or via Prisma client middleware setting transaction context parameters), guaranteeing security even if application queries omit filters.
* **Tenant Isolation Rules**:
* **Colaboradores**: Can only select rows from `SETTLEMENTS`, `SALES_RESULTS`, and `GOALS` where `user_id = current_setting('app.current_user_id')`.
* **Gerentes**: Can only select rows where `hotel_id = current_setting('app.current_hotel_id')`.
* **Líderes**: Can select rows within their assigned regions or teams (`region_id = current_setting('app.current_region_id')`).
* **Administradores / Analistas**: RLS is bypassed to allow system-wide computations and consolidated reporting.
* **Audit Trail Immutability**:
* The `AUDIT_LOGS` table has RLS policies that prevent `UPDATE` or `DELETE` actions for all users, including administrators. It is strictly write-only (`INSERT` operations only).
--- ---
## 6. Dual-Environment Docker Deployment Model ## 6. Dual-Environment Docker Deployment Model

View file

@ -1,6 +1,6 @@
# Project Roadmap & Implementation Plan # Project Roadmap & Implementation Plan
**Sistema de Remuneración Variable, Compensación y Comisiones - Hoteles Estelar** **Variable Remuneration, Compensation, and Commissions System - Hoteles Estelar**
--- ---
@ -8,41 +8,51 @@ This plan outlines the step-by-step path to construct, test, and host the platfo
## Phase 1: Foundation & Database Configuration ## Phase 1: Foundation & Database Configuration
* [ ] Initialize Next.js app with TypeScript and `npx` in the repository root. * [ ] Initialize Next.js app with TypeScript and `npx` in the repository root.
* [ ] Configure Vanilla CSS design tokens (variables, animations, grids/flex layouts, themes). * [ ] Configure Vanilla CSS design tokens (variables, layout standards, light/dark themes).
* [ ] Set up Prisma ORM and define the PostgreSQL schemas (`schema.prisma`) matching the ER diagram. * [ ] Define the PostgreSQL schemas in `schema.prisma` including:
* [ ] Verify container network connectivity between the Next.js app and the existing PostgreSQL Docker service. * Temporal versioning fields for plans (`version`, `validity_start`, `validity_end`).
* Idempotency and transaction fields for sales imports.
* Adjustment and original reference keys for settlements.
* [ ] Configure **PostgreSQL Row-Level Security (RLS)** policies on the schema for user/hotel data isolation.
* [ ] Execute initial database migration to seed basic structural tables (Regions, Hotels, Roles). * [ ] Execute initial database migration to seed basic structural tables (Regions, Hotels, Roles).
## Phase 2: Authentication & RBAC Core ## Phase 2: Authentication & Security Core
* [ ] Implement secure JWT session cookieless/cookie-based auth. * [ ] Implement secure JWT session cookie-based auth.
* [ ] Build a premium login interface with smooth CSS transition effects (no browser default controls). * [ ] Develop Prisma transaction middleware binding the active session's `user_id`, `hotel_id`, and `region_id` context to PostgreSQL settings to trigger RLS.
* [ ] Build a premium login interface with smooth CSS transition effects.
* [ ] Develop route guards and API middleware verifying user roles (RBAC authorization validation). * [ ] Develop route guards and API middleware verifying user roles (RBAC authorization validation).
## Phase 3: Compensation Configuration (Feature 1) ## Phase 3: Compensation Configuration (Feature 1)
* [ ] Implement UI forms and API endpoints for **Plan Creation** (HU-COM-001) with mandatory fields validation. * [ ] Implement UI forms and API endpoints for **Plan Creation** (US-COM-001) with mandatory fields validation.
* [ ] Implement **Calculation Rules config** (HU-COM-002) allowing tiers, multipliers, and cap inputs. * [ ] Enforce **Plan Versioning logic**: Modifying an active plan marks it inactive and duplicates it with an incremented version ID.
* [ ] Implement **Goal assignment UI** (HU-COM-003) for monthly/quarterly scopes. * [ ] Implement **Calculation Rules config** (US-COM-002) allowing tiers, scales, and cap parameters.
* [ ] Write comprehensive unit tests for versioning and duplicating plans. * [ ] Implement **Goal assignment UI** (US-COM-003) for monthly/quarterly scopes.
* [ ] Write integration tests for plan versioning replication.
## Phase 4: Data Import & Integrations (Feature 2) ## Phase 4: Data Import & Integrations (Feature 2)
* [ ] Create server-side Excel parser parsing sales sheets (HU-COM-004) with validation log feedbacks. * [ ] Create server-side Excel parser parsing sales sheets (US-COM-004) incorporating header-based **Idempotency key checks** to prevent duplicate uploads.
* [ ] Build file drag-and-drop loading screen featuring progress UI. * [ ] Build file drag-and-drop loading screen featuring progress and validation UI.
* [ ] Outline mock API connections for external ERP/PMS services (HU-COM-005) with auto-retry and logs. * [ ] Set up n8n workflows for automated sales integrations (US-COM-005) with retry mechanisms and callback endpoints.
## Phase 5: Settlement Engine & Approvals (Features 3 & 4) ## Phase 5: Settlement Engine & Approvals (Features 3 & 4)
* [ ] Build the Core Settlement calculation engine (HU-COM-006) handling individual/team tiers and caps. * [ ] Build the Core Settlement calculation engine (US-COM-006) handling individual/team tiers and caps.
* [ ] Implement **Simulation module** UI (HU-COM-007) displaying side-by-side comparative calculations. * [ ] Integrate **Retroactive Clawback/Adjustment logic**: Engine runs delta checks against past closed periods and creates adjusting line items for next payout.
* [ ] Build **Approvals workflow** panel (HU-COM-008) for Commercial Leaders (Approve/Reject with mandatory reason). * [ ] Build **n8n Webhook Test Branching**: Insert `IF` nodes checking for `/webhook-test` path segments to isolate test runs inside `TEST_DATABASE_URL`.
* [ ] Set up email/notification hooks dispatching notifications (HU-COM-009). * [ ] Implement **Simulation module** UI (US-COM-007) displaying side-by-side comparative calculations.
* [ ] Build **Approvals workflow** panel (US-COM-008) for Commercial Leaders (Approve/Reject with mandatory reason).
* [ ] Set up email/notification hooks dispatching notifications (US-COM-009).
## Phase 6: History, Auditing & Analytics (Features 5 & 6) ## Phase 6: History, Auditing & Analytics (Features 5 & 6)
* [ ] Build **Colaborador History dashboard** (HU-COM-010) showing individual historical progress and PDFs. * [ ] Build **Colaborador History dashboard** (US-COM-010) showing individual historical progress and PDFs.
* [ ] Wire up **Audit Logs trigger** (HU-COM-011) tracking every modification to rules/settlements. * [ ] Configure `@explita/prisma-audit-log` client extension (US-COM-011) to log data modifications with sensitive data masking (passwords, base salaries).
* [ ] Build premium **Financial Dashboard** (HU-COM-012) using chart widgets (ranking, variables, trends). * [ ] Set RLS block on the `AuditLog` table to make it strictly write-only (preventing edit/delete for all roles).
* [ ] Implement **PDF / Excel exporter service** (HU-COM-013) consolidating metrics by hotel/region. * [ ] Build premium **Financial Dashboard** (US-COM-012) using chart widgets (ranking, variables, trends).
* [ ] Implement **PDF / Excel exporter service** (US-COM-013) consolidating metrics by hotel/region.
## Phase 7: Deployment & Security Hardening ## Phase 7: Deployment & Security Hardening
* [ ] Write Dockge-compatible `docker-compose.yml` for the Next.js container. * [ ] Write `docker-compose.yml` defining the dual-service configuration (`app-prod` and `app-dev`) on different ports.
* [ ] Write environment variable validation and graceful exit code 0 script on `app-dev` startup.
* [ ] Add `git.yourdomain.com` or a sub-subdomain block in the host Caddyfile. * [ ] Add `git.yourdomain.com` or a sub-subdomain block in the host Caddyfile.
* [ ] Configure DNS resolution inside the WireGuard network. * [ ] Configure DNS resolution inside the WireGuard network.
* [ ] Implement log-stream redaction rules to prevent personal financial parameters from writing to server output.
* [ ] Final end-to-end security audits. * [ ] Final end-to-end security audits.