draftDraft
The host owns a bounded contribution intent, business purpose, and external identity before any provider surface opens.
Embed the credential-free Add a Place surface, record what the user reports, reconcile independently, and call a place published only when durable provider-backed evidence exists.
A state is not a UI label. It determines which actor may act, what evidence exists, what may be retried, and how recovery proceeds.
draftThe host owns a bounded contribution intent, business purpose, and external identity before any provider surface opens.
widget_openThe Mappls-hosted form is visible for one recorded attempt, while provider UI and submission remain outside the host contract.
submission_reportedThe contributor says the hosted form showed success, which is useful testimony but not a receipt or publication result.
publication_pendingAn operations process is checking supported Mappls search or an approved provider receipt for a stable published identity.
publishedterminalA supported provider surface returned a six-character Mappls Pin with attributable observation evidence.
rejectedA reviewer found a duplicate, invalid, unsafe, or otherwise non-publishable contribution and recorded why.
withdrawnterminalThe host stopped its own follow-up workflow at the contributor's request without claiming that the provider submission was deleted.
Commands express intent. The aggregate validates current state and invariants, commits one new version, and emits a fact in the same transaction.
create_contributionHost applicationplace_contribution.createdMap one bounded external case identity to one aggregate across network retries.
open_widgetContributordraftplace_contribution.widget_openedCreate at most one immutable attempt per command key and aggregate version.
report_submissionContributorwidget_openplace_contribution.submission_reportedRecord one acknowledgement for the active attempt without inventing a provider receipt.
queue_reconciliationHost applicationsubmission_reportedplace_contribution.reconciliation_queuedThe same scheduling key creates at most one pending transition and outbox event.
confirm_publicationOperations reviewersubmission_reportedpublication_pendingplace_contribution.publishedHash the supported evidence source, Mappls Pin, observation time, and source fingerprint before committing.
rejectOperations reviewersubmission_reportedpublication_pendingplace_contribution.rejectedPreserve the review decision, reason, and attempt version under the reviewer command key.
retryContributorrejectedplace_contribution.retriedCreate a new immutable attempt once while retaining the rejected attempt and decision in audit history.
withdrawContributordraftwidget_opensubmission_reportedpublication_pendingplace_contribution.withdrawnStop host follow-up once without representing this as provider-side deletion.
Keep provider responses, business identity, state, events, and side-effect delivery distinct so each can be reconciled safely.
Current host-owned state, business identity, purpose, ownership, and optimistic version.
contributionIdexternalIdstateversionpurposeownerImmutable record of each frame launch and contributor-reported outcome without provider-internal data.
attemptIdaggregateVersionopenedAtreportedAtdocumentedSourceUrlAttributable supported-source proof that a stable Mappls identity is observable.
mapplsPinevidenceSourceobservedAtsourceFingerprintreviewerAppend-only transitions and exactly-once-in-effect downstream notifications.
eventIdaggregateVersionactoridempotencyKeyoutboxStatusA hosted success screen or contributor report never proves publication.
No callback, browser message, receipt, moderation status, or withdrawal capability is invented when the public source does not document it.
Only provider-backed evidence containing a valid Mappls Pin can close the aggregate as published.
Every widget attempt is immutable and linked to the aggregate version that opened it.
Commands are idempotent, compare expected version, and commit audit plus outbox atomically.
Contribution text, actor identity, and precise location follow declared purpose, access, and retention boundaries.
Recovery changes durable truth only through the same rules as normal operation. A timeout is an unknown outcome, not evidence that nothing happened.
The host cannot load the established HTTPS source within its timeout and CSP boundary.
Keep the contribution in draft, explain the boundary, and offer an external open or later retry without claiming a submission.
No provider receipt exists and the contributor cannot confirm what the hosted surface showed.
Leave the attempt unresolved and allow a deliberate new attempt; never infer completion from iframe navigation.
Supported search resolves the same place identity or a reviewer establishes duplicate ownership.
Reject with duplicate reason and link the known Mappls Pin as context, not as evidence that this attempt created it.
Every bounded supported-source check returns no qualifying Mappls identity before the stated review deadline.
Keep pending or reject according to published host policy and expose the last check time without promising a provider SLA.
An in-flight command lacks acknowledgement while aggregate, command key, and outbox state are durable.
Reload the aggregate and replay the same command key; do not duplicate an attempt, decision, or notification.
Measure state age, event health, retries, reconciliation, and sensitive-data access alongside latency and error rate.
Only explicitly indexed evidence is linked. Empty sections are not backfilled with invented endpoints or package names.
8 labs · 5 hostile scenarios/api/places/search/json/apis/O2O/entity/{eLoc}mappls-app-widgetsmappls-rest-apis8 verified tests