{
  "ursId": "URS-021",
  "title": "Warn users before submitting a duplicate Bill-Only order",
  "timestamp": "2026-09-29T02:31:02.740Z",
  "durationMs": 55516,
  "config": {
    "inboxUrl": "http://localhost:43383",
    "dbHost": "localhost",
    "dbPort": 42299,
    "dbName": "cc_repinbox_dev"
  },
  "setup": {
    "status": "pass"
  },
  "scenarios": [
    {
      "name": "Step 1: Rep logs in and opens /billing/new",
      "status": "pass",
      "description": "Step 1: Rep logs in and opens /billing/new",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/screenshots/step-01-billing-new-step2.png"
      ],
      "explanation": "Logs in as Blair Bennett (Corveta rep) and opens /billing/new. Because Blair's organization has exactly one manufacturer partner (Vantis), +page.server.ts auto-selects the manufacturer and advances initialFormData.step to 2, so the form lands directly on the \"Surgery Details\" step. No duplicate warning appears yet because the sales account and procedure date fields are still empty — the duplicate check input builder returns null until both are filled.",
      "startedAt": "2026-09-29T02:31:14.300Z",
      "finishedAt": "2026-09-29T02:31:14.300Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/videos/step-01-login.webm"
    },
    {
      "name": "Step 2: No warning without an identity match",
      "status": "pass",
      "description": "Step 2: No warning without an identity match",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/screenshots/step-02-no-identity-no-warning.png"
      ],
      "explanation": "Selects ROSS Surgical Account Request and enters procedure date 2026-04-09 — the same (sales_account_id, procedure_date) pair used by the existing VBO-2025-002 (status=submitted). Since DF-2947 that alone is NOT enough: at least one identity signal (patient MRN, patient last name, or surgeon name) must also match, and blank-on-either-side never matches. The spec asserts no warning renders with the identity fields blank, and again after entering a non-matching patient MRN — proving the duplicate check is no longer over-eager.",
      "startedAt": "2026-09-29T02:31:27.967Z",
      "finishedAt": "2026-09-29T02:31:27.967Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/videos/step-02-warning-appears.webm"
    },
    {
      "name": "Step 2: Duplicate warning appears",
      "status": "pass",
      "description": "Step 2: Duplicate warning appears",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/screenshots/step-02-warning-visible.png"
      ],
      "explanation": "With the same account + date filled, entering VBO-2025-002's patient MRN (PT-76534, typed as a lowercase variant — MRN matching is trim + lowercase) supplies the required identity signal. The checkDuplicateBillingOrders remote query returns VBO-2025-002 flagged with patientIdComparison='match', DuplicateCheckState.blocked flips to true, and DuplicateOrderWarning.svelte renders the amber \"Possible Duplicate Submission\" alert listing the existing order with a View affordance and a \"(Same patient ID)\" badge, an acknowledge button (\"This is not a duplicate\"), and an \"Exit\" link. The NavigationFooter's Next button is blocked because manager.stepBlocked propagates from DuplicateCheckState.blocked.",
      "startedAt": "2026-09-29T02:31:29.397Z",
      "finishedAt": "2026-09-29T02:31:29.397Z"
    },
    {
      "name": "Step 3: Exit returns user to /billing",
      "status": "pass",
      "description": "Step 3: Exit returns user to /billing",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/screenshots/step-03-billing-list-after-exit.png"
      ],
      "explanation": "Re-triggers the warning (matching account, date, and patient MRN), then clicks the \"Exit\" link — an <a href=\"/billing\"> that leaves the wizard without submitting anything. The user lands on /billing. validate-db.ts independently confirms that no new billing_orders row was persisted during the run, proving the cancel path is non-destructive.",
      "startedAt": "2026-09-29T02:31:43.708Z",
      "finishedAt": "2026-09-29T02:31:43.708Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/videos/step-03-exit-and-review.webm"
    },
    {
      "name": "Step 4: Warning acknowledged, Next enabled",
      "status": "pass",
      "description": "Step 4: Warning acknowledged, Next enabled",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/screenshots/step-04-acknowledged-state.png"
      ],
      "explanation": "Re-triggers the warning (matching account, date, and patient MRN), then clicks \"This is not a duplicate\". The DuplicateCheckState.acknowledge() method sets confirmedNotDuplicate=true, which flips DuplicateCheckState.blocked to false. The alert transitions to its green \"Reviewed — Not a Duplicate\" state with an Undo button, and the Next button becomes enabled — proving the form is unblocked and the rep can proceed through the remaining wizard steps.",
      "startedAt": "2026-09-29T02:31:56.693Z",
      "finishedAt": "2026-09-29T02:31:56.693Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z/videos/step-04-acknowledge.webm"
    }
  ],
  "dbValidations": [
    {
      "name": "VBO-2025-002 still matches the duplicate-check criteria after the run",
      "query": "\n      SELECT id, order_number, status, procedure_date::text AS procedure_date, sales_account_id, patient_id\n        FROM billing_orders\n       WHERE order_number = $1",
      "status": "pass",
      "rows": [
        {
          "id": "ba000002-0000-4000-8000-000000000002",
          "order_number": "VBO-2025-002",
          "status": "submitted",
          "procedure_date": "2026-09-21",
          "sales_account_id": "fea7b8c9-d0e1-2345-0123-456789012345",
          "patient_id": "PT-76534"
        }
      ],
      "assertion": "VBO-2025-002 must still have status=\"submitted\", procedure_date=\"2026-09-21\", sales_account_id=\"fea7b8c9-d0e1-2345-0123-456789012345\" (ROSS Surgical Account Request), patient_id=\"PT-76534\" (the DF-2947 identity signal the spec matches on)."
    },
    {
      "name": "Cancel path did not persist a new billing_orders row",
      "query": "\n      SELECT COUNT(*)::int AS cnt\n        FROM billing_orders\n       WHERE sales_account_id = $1\n         AND procedure_date = $2",
      "status": "pass",
      "rows": [
        {
          "cnt": 1
        }
      ],
      "assertion": "Count of billing_orders at (sales_account_id=fea7b8c9-d0e1-2345-0123-456789012345, procedure_date=2026-09-21) must not increase during the run (baseline=1)."
    },
    {
      "name": "A duplicate-check-qualifying row still exists for the test (account, date)",
      "query": "\n      SELECT id, order_number, status, procedure_date::text AS procedure_date\n        FROM billing_orders\n       WHERE sales_account_id = $1\n         AND procedure_date = $2\n         AND status = ANY($3::text[])",
      "status": "pass",
      "rows": [
        {
          "id": "ba000002-0000-4000-8000-000000000002",
          "order_number": "VBO-2025-002",
          "status": "submitted",
          "procedure_date": "2026-09-21"
        }
      ],
      "assertion": "At least one billing_orders row at (sales_account_id=fea7b8c9-d0e1-2345-0123-456789012345, procedure_date=2026-09-21) must have status in BILLING_ORDER_RULES.DUPLICATE_CHECK_STATUSES (submitted, processing, po_missing, billed, completed) — otherwise the duplicate-warning query returns zero rows and the UX silently stops firing. VBO-2025-002 is expected to satisfy this."
    }
  ],
  "overallStatus": "pass",
  "outputDir": "/home/runner/_work/code/code/validation_test_results/urs-021-duplicate-order-warning/2026-09-29T02-31-02-739Z",
  "auditStartTime": "2026-09-29T02:31:01.158Z",
  "auditEventEvidence": [
    {
      "createdAt": "2026-09-29T02:31:09.348Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "blair.bennett@corvetasurgical.com",
      "userId": "17b8c9d0-e1f2-3456-1234-567890123456",
      "organizationName": "Corveta Surgical Group",
      "organizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "blair.bennett@corvetasurgical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:31:20.249Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "blair.bennett@corvetasurgical.com",
      "userId": "17b8c9d0-e1f2-3456-1234-567890123456",
      "organizationName": "Corveta Surgical Group",
      "organizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "blair.bennett@corvetasurgical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:31:34.776Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "blair.bennett@corvetasurgical.com",
      "userId": "17b8c9d0-e1f2-3456-1234-567890123456",
      "organizationName": "Corveta Surgical Group",
      "organizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "blair.bennett@corvetasurgical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:31:48.867Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "blair.bennett@corvetasurgical.com",
      "userId": "17b8c9d0-e1f2-3456-1234-567890123456",
      "organizationName": "Corveta Surgical Group",
      "organizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "blair.bennett@corvetasurgical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    }
  ],
  "auditQuery": "SELECT\n    ae.created_at,\n    ae.event_type,\n    ae.action,\n    ae.user_id,\n    u.email AS user_email,\n    ae.organization_id,\n    o.name AS organization_name,\n    ae.object_id,\n    ae.secondary_object_id,\n    ae.payload,\n    ae.route,\n    ae.trace_id\n  FROM audit_events ae\n  LEFT JOIN users u ON u.id = ae.user_id\n  LEFT JOIN organizations o ON o.id = ae.organization_id\n  WHERE ae.created_at >= $1\n    AND ae.organization_id = ANY($2::uuid[])\n  ORDER BY ae.created_at ASC",
  "auditAssertions": [],
  "emailAssertions": []
}