1.0.0-rc.1 · Release Candidate1 min read
AutoCore Listing Lifecycle, Ownership, and High-Risk Actions
Verified listing transitions, owner/dealer relationships, irreversible boundaries, and audit expectations.
Admin client actions include mark reserved, mark sold, and expire. The API controller also contains archive and reactivate endpoints that are not presented as ordinary UI controls in the reviewed page.
| Area | Source-verified boundary |
|---|---|
| Transition evidence | Record prior status, actor, reason, resulting status, public effect, index effect, and audit row. |
| Ownership | A seller/dealer label is context, not an authorization bypass. |
| Archive/reactivate | Documented as API-only unless the current UI proves the control. |
| Restoration | Do not claim archived listings can be restored without source proof. |
High-risk operation
Use the required permission, reason, confirmation, and post-action verification. UI visibility is not the authorization boundary.
Verification
Verify the route, permission, response state, audit outcome, and public effect before closing the task. Record unknown or configuration-dependent behavior as a limitation.