Release status: blocked. The source and package manifests are prepared for the lockstep 1.2.0 train, but no registry publication or public-release claim is valid until the sanitized ID-30 checklist and ID-31 pilot evidence pass pnpm s4:release.
English release notes
Adocommerce Kit 1.2 adds the Indonesia track without changing the default behavior of an upgraded host. The train includes:
- generic deferred and COD payments, signed dynamic shipping selections, fulfillment and return lifecycles, parcel attributes, payment instructions, and metadata;
- Midtrans Core API v2, Xendit Payment Requests
2024-11-11, and authorized kode-unik bank transfers; - importer-only Indonesian regions, opt-in kecamatan addresses, PMK 131/2024 PPN evidence, and exponent-0 IDR;
- Biteship API v1 rates/fulfillment, Komerce RajaOngkir API v1 rates/tracking, and idempotent COD remittance import;
- UU PDP consent, rights, portability, retention, legal-hold mechanisms, and the incident runbook;
- consent-aware WhatsApp Cloud notifications and regional Bahasa catalogs; and
- a Bahasa reference checkout that uses Cikarang address validation, provider-backed quotes when credentials exist, QRIS/BCA VA/GoPay/COD/kode-unik, explicit WhatsApp consent, and visible pending/expired/review states.
Host upgrade
Install every selected package at the exact same version, configure each package, review the host-owned diff, then migrate:
pnpm add @adocommercekit/core@1.2.0 @adocommercekit/storefront-api@1.2.0
pnpm add @adocommercekit/id@1.2.0 @adocommercekit/midtrans@1.2.0
pnpm add @adocommercekit/biteship@1.2.0 @adocommercekit/whatsapp@1.2.0
node ace configure @adocommercekit/core
node ace configure @adocommercekit/storefront-api
node ace configure @adocommercekit/id
node ace configure @adocommercekit/midtrans
node ace configure @adocommercekit/biteship
node ace configure @adocommercekit/whatsapp
node ace commerce:upgrade
node ace migration:run
node ace commerce:doctorAdd Xendit, RajaOngkir, or Stripe the same way when the host uses them. Never mix official package versions in a production pilot.
Catatan rilis Bahasa Indonesia
Adocommerce Kit 1.2 menambahkan jalur Indonesia tanpa mengubah perilaku bawaan host yang hanya melakukan upgrade. Rilis ini mencakup:
- pembayaran tertunda dan COD, pilihan ongkir bertanda tangan, pemenuhan dan retur, atribut paket, instruksi pembayaran, serta metadata generik;
- Midtrans Core API v2, Xendit Payment Requests
2024-11-11, dan transfer kode unik dengan otorisasi admin; - data wilayah melalui impor berlisensi, alamat sampai kecamatan, bukti audit PPN PMK 131/2024, dan IDR tanpa angka desimal;
- tarif serta pemenuhan Biteship v1, tarif serta pelacakan RajaOngkir Komerce v1, dan impor remitansi COD yang idempoten;
- mekanisme persetujuan, hak subjek data, portabilitas, retensi, legal hold, dan runbook insiden UU PDP;
- notifikasi WhatsApp Cloud berbasis persetujuan dan katalog regional Bahasa Indonesia; serta
- demo checkout Bahasa Indonesia dengan alamat Cikarang, pilihan QRIS/BCA VA/GoPay/COD/kode unik, persetujuan WhatsApp yang jelas, dan status kedaluwarsa atau perlu tinjauan yang terlihat.
Data wilayah tidak dibundel. Host produksi wajib mengimpor sumber yang hak distribusi dan pembaruannya telah disetujui. Mekanisme pajak dan UU PDP tidak menggantikan penilaian konsultan hukum atau kewajiban pengendali data merchant.
Support matrix
| Package | Tier | Supported 1.2 surface | Explicit boundary |
|---|---|---|---|
@adocommercekit/core |
Beta | Generic commerce engine and Indonesia-enabling seams | No official admin UI |
@adocommercekit/storefront-api |
Beta | Host-published 14-endpoint baseline | Dynamic demo routes remain host-owned additions |
@adocommercekit/stripe |
Beta | Existing PaymentIntent driver | Host owns complete SCA UX |
@adocommercekit/midtrans |
Beta | Core API v2 QRIS, VA, GoPay, retail channels, notifications | Refund matrix varies by channel |
@adocommercekit/xendit |
Beta | Payment Requests 2024-11-11 QRIS, VA, OVO/DANA flows |
Pinned API family only |
@adocommercekit/id |
Beta | Kode unik, regions, addresses, PPN, COD import, PDP | Importer-only data; PPnBM and certified Coretax mapping excluded |
@adocommercekit/biteship |
Beta | API v1 rates, waybill, tracking, insurance, COD carry | Enabled services require provider conformance |
@adocommercekit/rajaongkir |
Experimental | Komerce API v1 rates and available tracking | No emulated waybill, fulfillment, COD, or insurance |
@adocommercekit/whatsapp |
Experimental | Consent-aware Cloud API template notifications | Approved templates, durable queue, and host fallback required |
ID-30 release checklist procedure
-
Copy
release/s4/id30.example.jsonto a private release branch asrelease/s4/id30.json. -
Revalidate every linked official source and record the retrieval date, exact API/policy version, decision, and sanitized evidence reference.
-
Run controlled Midtrans and Xendit production self-purchases and the live refund matrix. Never archive credentials, raw payment instructions, or customer data.
-
Rehearse each supported database on a disposable populated baseline:
NODE_ENV=test node ace commerce:s4:seed-100k node ace commerce:upgrade --yes node ace migration:run --force NODE_ENV=test node ace commerce:s4:seed-100k --verify-onlyRepeat with SQLite, PostgreSQL, and MySQL, recording at least
100000surviving orders per dialect. -
Run pack/install, security-negative, documentation, canary, dataset, native-language, and counsel checks. Record all seven global brownfield checks: all-dialect concurrency, populated additive migration, existing-host inertness, public surface publication, pristine
node ace configureinstall, security negatives, and official-source/version revalidation. -
Set
secretScanonly after the archived evidence has been scanned and manually reviewed. The validator rejects common credential formats and secret-bearing fields, but this structural check does not replace the manual review. -
Run
pnpm s4:id30 -- --evidence release/s4/id30.json. A pending, missing, malformed, credential-bearing, or sub-threshold record fails closed.
ID-31 pilot retrospective contract
The retrospective is not populated until the real pilot occurs. Copy release/s4/id31.example.json to release/s4/id31.json and record only sanitized metrics for these fixed cohorts:
- fashion UMKM: kode-unik and COD;
- electronics: Midtrans; and
- F&B: QRIS and instant courier.
Each merchant must reach a production transaction within 72 hours of pilot start. At least 90% of observed friction must be filed. Any unresolved issue that requires reopening a frozen generic seam blocks release. Validate with pnpm s4:pilot -- --evidence release/s4/id31.json.
Each cohort also records sanitized vault/evidence references for the merchant, named owner, data-processing boundary, support expectations, target pilot date, and completed setup. The engineering-support budget is fixed at four days; recorded use above that budget fails the gate.
The published retrospective must report cohort dates, time-to-first-transaction, observed/filed friction counts, engineering support days, resolved issues, and remaining boundaries. It must not contain merchant personal data, credentials, payment instructions, provider payloads, or unredacted support logs.
Publication gate
Run the manually dispatched S4 Indonesia release gate workflow against the exact release commit and sanitized evidence paths. It reruns source checks, pack/install, documentation, both evidence validators, and the lockstep manifest check. Only after it passes may maintainers tag and publish 1.2.0 and move the release notes from candidate to released.
Backlog after 1.2
- official admin UI and admin API;
- automatic bank-mutation matching for kode unik;
- certified e-Faktur/Coretax mapping and PPnBM;
- bundled region data unless redistribution rights later permit it;
- core-wide localization of pre-existing errors;
- Komship-specific COD or unsupported RajaOngkir fulfillment emulation;
- additional provider API families without a new conformance decision; and
- stable support-tier promotion, which requires later independent-team adoption evidence.