# Phase 5 Report - History, Moderation, Closing, and Exports

Date: 2026-07-15

## Scope

Phase 5 implemented the history, moderation, closing, dashboard, and export scaffold for Wedding Reels. This phase did not begin final exports beyond manifest/checksum planning, AirBridge integration, camera/image pipeline expansion, or unrelated Phase 6 work.

The governing product contract files were not intentionally changed:

- `MASTER_SPEC.md`
- `DATABASE_SCHEMA.sql`
- `OPENAPI.yaml`
- `CODEX_PROMPTS.md`

## Append-Only History Rule

History is append-only.

Replacement, moderation, restore, pause, resume, close, final snapshot, and export actions are represented as additional records/events. They do not rewrite or delete prior history events.

The live/current occupant projection may change, but the historical event stream keeps the full story: default art, arrivals, removals, guests getting kicked off, moderation actions, restores, and guests winning their way back.

## Files Changed

- `package.json`
- `packages/core/src/history-model.js`
- `packages/core/src/index.js`
- `packages/ui/src/history-view.js`
- `packages/ui/src/index.js`
- `apps/history/index.html`
- `apps/history/src/history.js`
- `apps/history/css/history.css`
- `apps/admin/index.html`
- `apps/admin/src/admin.js`
- `apps/admin/src/admin.css`
- `server/public/index.php`
- `server/src/Controllers/HistoryController.php`
- `server/src/Services/AdminPhase5Service.php`
- `server/src/Services/HistoryService.php`
- `server/src/Services/RealtimeEventService.php`
- `server/database/migrations/005_phase5_history_admin_exports.sql`
- `server/tests/Unit/Phase5WorkflowTest.php`
- `tests/phase0/ci-local.mjs`
- `tests/phase4/run-phase4-tests.mjs`
- `tests/phase5/run-phase5-tests.mjs`
- `docs/PHASE5_REPORT.md`

## Behaviorally Verified

The available Node-based tests verify:

- Appending history events does not mutate previous history arrays.
- Guest history records arrival, removal, and re-entry without overwriting earlier entries.
- Symbol timelines include default art and append replacement, moderation, and restore records as new versions.
- Chronological filtering and pagination preserve event order.
- Moderation and restore are represented as new events.
- Final snapshots are frozen/read-only data products.
- Export manifests include required files and deterministic checksums.
- The desktop historical viewer remains read-only.
- Phase 5 routes and services are present and append-only oriented.
- Existing Phase 0 through Phase 4 behavioral checks still pass.

## Statically Verified

The PHP services and routes were inspected by the Phase 5 test suite but were not executed under PHP:

- `HistoryService` exposes chronological history, symbol timelines, guest histories, final snapshot data, and dashboard summary data.
- `AdminPhase5Service` appends moderation, restore, pause, resume, close, final snapshot, and export records without rewriting the event log.
- `HistoryController` exposes public read-only history plus authenticated administrative moderation, restore, closing, and export endpoints.
- `server/public/index.php` wires the Phase 5 routes.
- Migration `005_phase5_history_admin_exports.sql` defines durable tables for history events, occupant versions, moderation actions, final snapshots, and export packages.
- PHPUnit specifications for Phase 5 runtime verification exist and are explicitly skipped unless `WR_ENABLE_PHP_RUNTIME_TESTS` is enabled in a PHP runtime.

## Runtime-Blocked Release Checks

The following remain release-blocking because this environment does not currently provide PHP, Composer, Docker, MySQL, or Redis:

- PHP 8.3 syntax checks against every PHP file.
- Composer validation and dependency installation.
- PHPUnit execution for history, dashboard, moderation, restore, close, export, admin authorization, and read-only desktop policy.
- Applying migrations `001` through `005` to a clean MySQL 8 database.
- Starting Apache/PHP, MySQL, Redis, and the realtime gateway together.
- Exercising actual HTTP endpoints for history, dashboard, moderation, restore, pause, resume, close, export, and canonical state.
- Verifying Redis/distributed lock behavior.
- Verifying durable outbox publication after committed PHP/MySQL transactions.
- Verifying actual ZIP/export package generation.
- Verifying Phase 4's two simultaneous valid commits against the same wedding and symbol.

## Commands Run

Passed:

```text
node --check packages/core/src/history-model.js
node --check packages/ui/src/history-view.js
node --check apps/history/src/history.js
node --check apps/admin/src/admin.js
node tests/phase5/run-phase5-tests.mjs
npm run ci:local
node -e "... JSON parse check ..."
```

Phase 5 test result:

```text
ok - history append is immutable and keeps every enter/remove/re-enter event
ok - guest history records entry, removal, and re-entry without overwriting
ok - symbol occupant chain includes default art and append-only replacements/restores
ok - filtering and pagination preserve chronological order
ok - moderation and restore are represented as new events
ok - final snapshot is frozen and export manifest lists required files with checksums
ok - historical viewer remains read-only
ok - server Phase 5 routes and services are present and append-only oriented
ok - PHP Phase 5 runtime specs exist and are explicitly blocked
phase 5 tests passed
```

Full local CI result:

```text
phase 0 tests passed
phase 1 tests passed
phase 2 tests passed
phase 3 tests passed
phase 4 tests passed
phase 5 tests passed
local CI checks passed
```

Blocked locally:

```text
php -v                  -> command not found
composer --version      -> command not found
docker --version        -> command not found
mysql --version         -> command not found
redis-server --version  -> command not found
```

## Moderation and Restore Behavior

Moderation hide/reject actions create `MODERATION_HIDDEN` or `MODERATION_REJECTED` events.

Restore actions create `OCCUPANT_RESTORED` events.

Neither action deletes prior replacement history. The current occupant projection can be updated for live display, but the history stream keeps all prior occupant versions.

## Dashboard and History Views

The shared UI history renderer now supports:

- chronological history
- guest histories
- symbol timelines
- final snapshot display
- dashboard summary cards

The history application remains read-only. The admin application consumes the same shared history/dashboard rendering modules instead of duplicating history logic.

## Export Scaffold

The export service creates a deterministic manifest containing package metadata, event/state artifacts, file entries, and checksums. Actual archive creation is still runtime-blocked until PHP and the required archive/image dependencies are executable.

## Remaining Technical Debt

- Execute all blocked PHP/MySQL/Redis/Docker checks in CI or a local runtime with PHP 8.3.
- Replace export scaffold with fully executed archive generation once ZipArchive or an approved archive implementation is available.
- Add HTTP-level authorization tests for every Phase 5 admin endpoint.
- Run browser smoke tests for history and admin dashboard views.
- Keep Phase 4 concurrent-commit verification as a release blocker until MySQL/Redis runtime testing is available.

## Status

Phase 5 is implementation-complete within the available JavaScript/static environment.

Backend runtime verification remains blocked and release-blocking until PHP 8.3, Composer, MySQL 8, Redis, and Docker or equivalent local services are available.
