A distributed workflow needs a localized repair without weakening observability or rollback safety. The affected area is checkout journey.
Repair the checkout journey command handling implementation so it accepts first operations, recognizes safe repeats, and rejects key reuse with a different payload.
Evidence
- Affected surface: Balanced full-stack / checkout journey.
- Observed failure family: enforce idempotent operations.
- Scope policy: region must equal eu-west.