# Changelog of Romania CUI Check & Watch: ANAF VAT, e-Factura, Inactive (`clearsource/ro-company-status`) Actor

- **URL**: https://apify.com/clearsource/ro-company-status/changelog.md
- **Full Actor documentation**: https://apify.com/clearsource/ro-company-status.md

## Changelog

### 0.1.4 — 2026-10-07 (private build, not listed)

- Rate limiter moved to the product host (one host per product, Petre's hosting rule 2026-10-07; ADR-001 amendment): `PDA_LIMITER_URL` is now `https://clearsource.ppftec.com/limiter` (the site Worker forwards `/limiter/*` to the anaf-limiter Worker over a Service Binding; the old `https://anaf-limiter.petrepopa33.workers.dev` is switched off). The pin is now host **and** path: https, exactly `clearsource.ppftec.com`, path exactly `/limiter`, no credentials, query or fragment; the request URL is built from the constant, never from the input. Redirects stay refused. The run log now names the limiter endpoint in use (never the secret).
- Host move (Petre's hosting rule, 2026-10-07): `privacy_notice_url` is now `https://clearsource.ppftec.com/privacy` (the old `https://ppftec.com/public-data-api/privacy` answers 301 to it); README updated.

### 0.1.3 — 2026-10-04 (private build, not listed)

- D-LIM-T1: a limiter slot whose round trip took longer than 400 ms is not used (the slot-time estimate would be too uncertain); a new slot is requested. At most 3 slow slots per ANAF request, then the run fails closed ("rate-limit service too slow to time the request safely"), with no ANAF call. Each discarded slot still counts against the shared daily budget (20,000/day).

### 0.1.2 — 2026-10-04 (private build, not listed)

Release conditions R1–R8 of the legal memo (`docs/compliance/legal-research-memo-d6-2026-10-04.md` §5.1), code parts:

- R1: the central limiter enforces a global daily budget (default 60,000 ANAF slots per UTC day, var `DAILY_SLOT_LIMIT`, persisted); when it is used up the actor stops before any ANAF call with "the shared daily ANAF request budget is used up; try again after 00:00 UTC". Tests confirm: no proxy in the code, the descriptive User-Agent goes out with every ANAF request, back-off 5/10/20/40 s.
- R2: CNP-like redaction now walks every string value taken from the ANAF response, at any depth (not a fixed field list); a property test injects a CNP into each source field in turn.
- R4: every record carries `privacy_notice_url` (`https://ppftec.com/public-data-api/privacy`, one constant in `src/sources.ts`, **pending hosting**); README links it. Output schema 1.3.0 (additive, optional field).
- R5: test that an accepted objection removes the CUI from the watch store on the next run, with no ANAF request, output or charge for it.
- R6: README keeps "Sursa: ANAF" and makes no official / certified / OGL claim (one explicit disclaimer sentence; test).
- Spacing raised from 1,200 ms to 1,500 ms (limiter + per-run guard; README throughput now about 4,000 CUIs per minute shared): the deployed contract test had measured client-side gaps of 891–969 ms. The limiter client now aims at the slot time (midpoint of the round trip + `wait_ms`) instead of sleeping `wait_ms` from receipt. Production daily budget 20,000 slots.
- R8: README "Stop / takedown" section: support@ppftec.com, answered within 24 hours.

### 0.1.1 — 2026-10-04 (private build, not listed)

Fix rounds after QA (`docs/qa/report-ro-company-status-2026-10-04.md`) and security review (`docs/security/anaf-limiter-and-company-status-review-2026-10-04.md`).

- DEF-1: without pay-per-event pricing a run is no longer truncated (only a real budget limit stops it); on Apify an unpriced build fails loud before any call unless `PDA_ALLOW_NO_PPE=1` (private builds only). Watch state is persisted when events are unpriced.
- DEF-2 / NEW-C2: new-format trade-register numbers (J/F/C + year 1990–current + 6 digits + county 01–52 + 1 digit, e.g. `J2004000552406`) are no longer nulled as CNP-like; J/F/C followed by a CNP still is.
- DEF-3 / CS-SEC-06: `INVALID_INPUTS` echoes a value only if it holds at most 10 digits (after NFKC); 12-digit variants, CNPs split by any separator and full-width digits are stored as `null`.
- DEF-4: a dry run with zero valid CUIs exits 1.
- DEF-6: cap messages read "5,000" / "10,000".
- DEF-7: the replay transport skips fixture files without a `found[]` list.
- DEF-8: README states that the once-a-day floor applies to companies; sole traders are re-queried, never charged or reported.
- DEF-9: `resetWatch` works under the kill switch, `PDA_DISABLED_MODES=watch` and the pending gates (it only deletes the customer's own store; no limiter or ANAF call, no charge).
- DEF-10: live and deployed tests run only with an explicit opt-in set in the shell (`PDA_LIVE_ANAF_APPROVED=P1-02`; Worker `LIMITER_CONTRACT=1`).
- CS-SEC-03: health mode needs `PDA_HEALTH_ENABLED=1`, a secret input `healthToken` matching the secret `PDA_HEALTH_TOKEN` (≥ 32 chars) and, if set, `PDA_MAINTAINER_USER_ID`.
- CS-SEC-07: `.actor/actor.json` references secrets as `@pdaLimiterSecret`, `@pdaSuppressionPepper`, `@pdaHealthToken`; no maintainer switch is declared there.
- LIM-SEC-10 (limiter): local tests use explicit bindings only and refuse to run if `.dev.vars` exists; contract values live in `.contract.env`; the limiter secret was rotated.
- Output schema 1.2.0 (provenance envelope 1.1.0, additive; emitted records unchanged). Shared core updated (spacing never fires early).

### 0.1.0 — 2026-10-04 (private build, not listed)

- Provenance envelope 1.1.0 vendored (additive: `personal_data` adds `minimised`, `envelope_version` accepts `1.1.0`); output schema `ro-company-status/record` 1.2.0 references it; shared `src/core/provenance.ts` updated (identical in all actors). Emitted records unchanged (`envelope_version` `1.0.0`; `personal_data` `none` or `public-register-natural-person`).
- Lookup and watch modes per `docs/spec/ro-company-status-v1.md` (T1–T8): CUI check digit, CNP rejection, caps (10,000 / 5,000 / 20,000 raw), chunks of ≤ 100 CUIs, de-duplication.
- Central rate limiter client (`workers/anaf-limiter`, ADR-001): a slot before every ANAF attempt, fail closed (no ANAF request without a slot), pinned limiter host.
- Mapping with minimisation (sole traders: no street-level address; phone, fax, IBAN never output), CNP-like redaction, provenance envelope 1.0.0, output schema v1.1.0.
- Source shape pinned against the first approved live sample (2026-10-04): no top-level `cod`/`message`, `perioade_TVA` is an array, empty values are `""`, extra key `date_generale.data_inreg_Reg_RO_e_Factura` (accepted, not output).
- Watch mode (C1–C12): fixed store name, daily floor, pruning, no history, sole traders excluded, confirmation of disappearances, lock; gated off on Apify until D6.
- Suppression list (HMAC with secret pepper), kill switches (`PDA_KILL_SWITCH`, `PDA_DISABLED_ADAPTERS`, `PDA_DISABLED_MODES`, limiter-side `ANAF_DISABLED`), dry run, health mode.
- Pay-per-event charging: `company-check`, `watch-check`, `status-change`, chunks sized to the remaining budget.
