Phase Gates — Commands and Acceptance Criteria
Gates enforce test-before-next-step. Run from repository root:
cd /Users/marchon/apps/zapier
npm run gate:N
npm run gate:all runs gates 0 … 12 sequentially and exits non-zero on first failure.
Gate 0 — Structure and documentation
npm run gate:0
| Check |
Requirement |
| Layout |
TODO.md, README.md, middleware + zapier dirs, docs tree |
| Architecture |
docs/architecture/overview.md, nats-subjects.md |
| Developer |
docs/developer/debugging.md, docs/developer/modules/*.md |
| Plan |
docs/plans/phase-gates.md |
Gate 1 — Debug facility
npm run gate:1
Tests: verae-zapier-middleware/test/unit/debug*.test.js
| Check |
Requirement |
| Off by default |
No output when DEBUG_VERAE unset |
| Namespace filter |
auth does not emit nats lines |
| Redaction |
Tokens/passwords not present in formatted output |
| Trace |
Child spans inherit traceId |
Gate 2 — HTTP shell
npm run gate:2
| Check |
Requirement |
| Health |
GET /health → 200 { status: "ok" } |
| Errors |
Thrown AppError → JSON { error, code } |
| Config |
Reads NATS and debug env keys |
Gate 3 — Stores
npm run gate:3
| Check |
Requirement |
| Tenants |
API key maps to tenant |
| Limits |
Plan + enterprise contract |
| Webhooks |
Tenant isolation |
| Persist |
Reload preserves state |
Gate 4 — Tokens + Verae client
npm run gate:4
| Check |
Requirement |
| HMAC |
Bad signature rejected |
| Mock job |
create → wait → completed |
| HTTP debug |
No Authorization values logged |
Gate 5 — Auth + entitlements
npm run gate:5
| Check |
Requirement |
| Me |
Valid API key |
| 401 |
Invalid key |
| 402 |
Over quota |
Gate 6 — Sync HTTP API (NATS off)
NATS_ENABLED=false MOCK_VERAE=true npm run gate:6
| Check |
Requirement |
| Timestamp |
202 + jobId |
| Wait |
completed status |
| Verify |
boolean valid |
| Webhooks |
subscribe stored |
Gate 7 — NATS infrastructure
npm run gate:7
| Check |
Requirement |
| Streams |
Created/idempotent ensure |
| Pub/sub |
One message round-trip |
| Flag off |
App boots without NATS |
Gate 8 — Workers
NATS_ENABLED=true MOCK_VERAE=true npm run gate:8
| Check |
Requirement |
| Watch→event |
Terminal event published |
| Webhook |
Mock receiver got POST |
| Queue group |
No double complete |
Gate 9 — Wait via NATS
npm run gate:9
| Check |
Requirement |
| Success |
Wait returns completed |
| Timeout |
Returns pending + jobId |
Gate 10 — Tenancy
npm run gate:10
| Check |
Requirement |
| Signup |
free + apiKey |
| Enterprise |
requires contract |
Gate 11 — Zapier package
npm run gate:11
| Check |
Requirement |
| Auth module |
fields + test URL |
| Creates |
correct middleware paths |
| Trigger |
subscribe shapes |
Gate 12 — E2E local compose
npm run gate:12
| Check |
Requirement |
| Stack |
health green |
| Paths |
async + wait + hook |
Gate 13 — Production smoke (opt-in)
PRODUCTION_SMOKE=1 npm run gate:13
Requires real secrets; skipped in default gate:all.
Gate 14 — Human acceptance
Manual checklist in TODO.md (not automated).
Gate 15 — Hardening
Checklist + load notes in TODO.md.
Recording results
After each green gate, update the Gate log table in TODO.md with date and pass.