# ANTIGRAVITY CMS: RECOMMENDATIONS

Based on the forensic audit of the Clinic Management System (CMS), the following structural, security, and architectural recommendations are proposed:

## 1. Security & Tenant Isolation

- **Fix Cross-Tenant Data Leakage (BUG-001):** The `BranchScope` currently ignores tenant constraints entirely if `BranchContext` is not set. The public API endpoints do not establish a context, allowing cross-tenant IDOR attacks.
  - *Recommendation:* Do not silently bypass scopes. Update `BranchScope` to throw a `BranchForbiddenException` if no context is found, or update public endpoints to explicitly declare their branch context before making model queries.
- **Fix Host Header Injection (BUG-002):** The QR Code generation for document authenticity uses `route()`, reading the `Host` header.
  - *Recommendation:* Enforce the trusted proxy configuration rigorously or set `URL::forceRootUrl(config('app.url'))` inside the PDF generation service to ensure absolute, server-configured URLs instead of relying on the client's HTTP Host header.

## 2. Database & Data Integrity

- **Fix Unique Constraints with Soft Deletes (BUG-004):** The `users.email` and `patients.mrn` constraints break when a deleted record occupies the unique slot.
  - *Recommendation:* Either drop `SoftDeletes` from these identifier tables, use partial indexes (e.g., PostgreSQL `WHERE deleted_at IS NULL`), or include `deleted_at` in the unique compound index `UNIQUE (email, deleted_at)`.
- **Atomic Print Counters (BUG-003):** 
  - *Recommendation:* In `PrescriptionService::recordPrint()` and `LabOrderService::recordPrint()`, replace `$model->forceFill(['print_count' => $model->print_count + 1])->save()` with `$model->increment('print_count')` to prevent lost updates during concurrent requests.
- **Deadlock Avoidance in Pharmacy Dispensing:**
  - *Recommendation:* In `DispensingService::dispense()`, sort the `$lines` array by `drugId` before iterating through it to allocate batches. This will guarantee that all concurrent transactions request locks on drugs in the same order, eliminating circular wait deadlocks.

## 3. Application Logic & User Management

- **API Access for Inactive Users:**
  - *Observation:* Deactivated users (`is_active = false`) keep their API tokens and can hit endpoints that don't invoke `authorize()` or `Gate` checks (e.g., `/api/v1/me`).
  - *Recommendation:* While the `Gate::after` closure successfully blocks these users from protected actions, consider adding a global middleware (`CheckUserIsActive`) that returns `403 Forbidden` for all authenticated requests if `is_active` is false, ensuring immediate lockout across all API endpoints.

## 4. Architecture

- **Maintain Strict Service Boundaries:** The current separation of concerns between `Laboratory/Services` (order handling) and `Billing/Services` (money handling) is exemplary. Continue enforcing this pattern; avoid leaking domain concepts (like pricing) across module boundaries except through explicit DTOs.
- **File Upload Quarantine:** The implementation in `PatientUploadService` (sniffing MIME, quarantining, and requiring explicit staff approval before merging into the clinical record) is highly secure. Apply this pattern to any future inbound integrations (e.g., third-party lab result imports).
