# Rule 01 - Item ids are opaque

## Purpose

Ids leaked sequence information, letting a customer estimate our total item
count from their own ids. Two prospects asked about it during security review.

## Applies to

Every id returned by the public API.

## Mandatory rules

1. Public ids are random, not sequential.
2. No endpoint accepts an internal integer id.

## Enforcement

- Mechanism: `tests/test_opaque_ids.py`
- Type: structural test over the `src/` AST.

**Partially enforced - do not read a green run as full coverage.**

| Mandatory rule | Enforced? | By what |
|---|---|---|
| 1. Public ids are random, not sequential | **no** | nothing - see gap below |
| 2. No endpoint accepts an internal integer id | yes | no field named `id`/`*_id` under `src/` may be annotated `int` |

**The gap.** This repository contains no id generation and no public API
surface, so rule 1 has nothing to assert against. It is unenforced, not
enforced-and-passing. When an id generator lands, extend
`tests/test_opaque_ids.py` to assert non-sequentiality at that point; until
then this rule rests on review alone.
