A maker can own a shop and listings without owning everybody else’s.
v0.12.11 adds a real moderation-review state machine and frozen public catalog snapshots on top of the authenticated D1/R2 maker workflow. Shopper reads now come from an approved snapshot instead of the maker's live editable listing record.
Catalog schema + authorization contract
These calls hit the deployed Pages Function and D1. The self-test creates two disposable maker fixtures plus a shopper fixture, tests ownership and capability denial, then removes the test records.
Shopper does not equal Maker
Use an active QA Shopper Session from Identity QA, then test this endpoint. The server should return 403 because that account has Shopper capability only.
If you already revoked your QA session, start a new Shopper Session in Identity QA first. A 401 means there is no active session; a 403 with Shopper-only capabilities is the PASS condition here.
Authenticated Maker CRUD
Then start a QA Maker Session in Identity QA and run a disposable server create → read → update → list → delete probe. The fixture cleans itself up.
Maker catalog ownership checks
Record only evidence you actually perform on clarawidetest.
Real shop/listing migration gates
Leave these Not Checked until each remaining production control is genuinely complete. The staging Maker UI connection alone is not a production credential or media system.
Record ownership / listing defects
Catalog blockers & defects
RECENT SERVER RUNSExport or reset this QA layer
Export captures checks, findings and server-run evidence from this browser.
