# QODY Kitchen KDS live update — MC #107293 / #106857 — 2026-08-18

# QODY Kitchen KDS live update — final evidence

**Status:** Functionally implemented, deployed, and live-verified on demo and production surfaces.  
**Tasks:** MC #107293 (missed KDS updates), MC #106857 (demo Kitchen credential blocker), MC #107308 (deterministic first health request).

## Incident and confirmed causes

An already-open Kitchen Display System could remain `Uzivo` while a new order was absent until manual `SINKRONIZIRAJ`. A controlled pre-fix reproduction dropped the new-order WebSocket frames: the order remained absent after 20 seconds and appeared immediately after manual sync. Confirmed causes were:

1. order events could be broadcast before the transaction committed, so a separate listener connection could fetch no payload;
2. PostgreSQL NOTIFY/WebSocket delivery is intentionally non-durable and the KDS had no bounded authoritative replay;
3. the existing-order pay-at-table transition had no KDS event;
4. the demo KITCHEN fixture password in the long-lived database no longer matched the documented fixture, blocking exact-role UAT.

## Implemented remediation

- Backend broadcasts order/payment/lifecycle events only after commit.
- `ORDER_PAYMENT_MODE_UPDATED` maps to the KDS `order_update` wire event.
- Visible Kitchen boards reconcile from the authoritative database every 10 seconds, pause while hidden, refresh on visibility return, abort hung requests, coalesce overlaps, and reject stale responses that race newer WebSocket events.
- Pending-payment and terminal orders remain excluded; no unbounded polling was added.
- A demo-only repeatable Flyway migration repairs the canonical KITCHEN fixture without exposing a reset endpoint or loading in production.
- E2E login now uses the real httpOnly-cookie KITCHEN form path; obsolete bearer/localStorage and OWNER fallbacks were removed. It waits deterministically for the initial `/staff/orders` response and connected WS label.

## Source, reviews, and rollout

- Core fix commit `14d38c6b68381a74e73375b712f898d87af8734d`, PR **347**, merged and deployed to production in build **1126**.
- Credential repair commit `b884161362c2f05243c21812ca70dbb56ba22dae`, PR **355**, policy build **1135 PASS**, merged.
- Exact-role harness commit `c47d846457d42c4a2937e9fc7cbbb630e20b798d`, PR **358**, policy build **1143 PASS**, merged as `5aca15661402ccfede109c70ec67063a3e2cd9ee`.
- Demo API canary `qody-api--bc227a76-1140`: health/RLS PASS, 100% traffic; previous serving revision retained as rollback.
- Demo Kitchen `qody-staff-kitchen--0000031`: Healthy/Provisioned at 100%; former serving revision retained at 0% rollback.
- Production Kitchen `qody-staff-kitchen-prod--71fd83c7-1126`: Healthy/Provisioned at 100%.
- Staff-Kitchen unit suite 28/28 PASS; backend tests PASS; real-PostgreSQL credential migration test PASS.
- CodeCraft review P0=0/P1=0; Redžo and Gemini final verdicts APPROVE.

## Exact live acceptance proof

The final test uses the canonical **KITCHEN** role and real cookie authentication. No OWNER fallback, token injection, manual sync, or reload is permitted.

| Flow | Result | Evidence |
|---|---|---|
| K-02 normal WebSocket | **PASS** | Order appeared in **47 ms** with two order-related WS frames |
| K-02b missed frame | **PASS** | Exactly one `order_created` frame deliberately dropped; one card recovered in **9,919 ms** |
| Duplicate guard | **PASS** | Exactly one recovered KDS card |
| Cleanup | **PASS** | Both test orders canceled successfully |
| Credential causal check | **PASS** | Canonical demo KITCHEN login changed from pre-deploy 401 to post-deploy 200/KITCHEN |

## Evidence paths

- Final manifest: `/Users/makinja/system/evidence/106857/kitchen-live-update/final-live-verification.json`
- Live test log: `/Users/makinja/system/evidence/106857/kitchen-live-update/k02-k02b-live-r5.stdout.log`
- Screenshots and WS frames: `/Users/makinja/system/evidence/106857/kitchen-live-update/live-proof-deterministic/`
- API canary/retention: `/Users/makinja/system/evidence/106857/kitchen-live-update/manual-api-canary-result.json`
- Root-cause verdict: `/Users/makinja/system/evidence/107293/root-cause-verdict.md`
- Dual review: `/Users/makinja/system/evidence/107293/dual-review/dual-review-summary.json`

## Administrative note

Company Mesh verification prompts timed out because no responder payload was available. This was an orchestration-gate failure, not a product/test failure. No peer PASS was fabricated; closure is based on deterministic live Playwright evidence, Azure policy builds, merged PRs, deployed revision identity, cleanup proof, and independent Redžo/Gemini/CodeCraft reviews.