# Brands — Contracts

> Produced by the Reversa **Writer** (phase: generation) · doc_level: `complete`
> Generated on 2026-09-21

**Confidence scale:** 🟢 CONFIRMED · 🟡 INFERRED · 🔴 GAP

External HTTP contract exposed by the `brands` unit — the Laravel `resource settings/brand` (`BrandController`) under the admin group (`['web','admin']`) with the `settings` prefix. It is a server-rendered **HTML/form** CRUD (redirect-back, not JSON), requires an authenticated admin session, and is a thin Encore\Admin `ModelForm` scaffold. `store`/`update`/`destroy`/`show`/`create` are framework defaults driven by `form()`; only `index`/`edit`/`grid`/`form` are overridden. 🟢 (`routes/web.php:86-87`, `BrandController.php`)

---

## Resource surface `settings/brand` 🟢

| Method | Path | Purpose | Notes |
|--------|------|---------|-------|
| GET | `settings/brand` | List + inline create form | Two-column: grid (id/name/description) + `Widgets\Form`. 🟢 (`:19-40`) |
| POST | `settings/brand` | Create a brand | `name` (required) + `description`; `ModelForm::store`. 🟢 (`:75-81`) |
| GET | `settings/brand/{id}/edit` | Edit form | `form()->edit($id)`; unknown id → `404`. 🟢 (`:42-48`) |
| PUT/PATCH | `settings/brand/{id}` | Update a brand | `name` (required) + `description`; `ModelForm::update`. 🟢 (`:75-81`) |
| GET | `settings/brand/{id}` (show) · GET `settings/brand/create` · DELETE `settings/brand/{id}` (destroy) | Framework defaults | Not surfaced in the UI: no create button, delete disabled on all rows. 🟡 (`:59,69`) |

- **Auth:** required; anonymous → `302 auth/login`. 🟢 (`routes/web.php:24-28`)
- **CSRF:** required on POST/PUT/DELETE (Laravel `web` middleware; Encore\Admin forms emit the token). 🟢
- **Create request (`POST settings/brand`):**

  | Field | Type | Required | Notes |
  |-------|------|----------|-------|
  | `name` | string | ✅ | `rules('required')`. 🟢 (`:78`) |
  | `description` | string | ❌ | Free text. 🟢 (`:79`) |

- **Update request (`PUT settings/brand/{id}`):** same field set (`name` required, `description`). 🟢 (`:78-79`)
- **Responses:** `200` HTML for list/edit; `302` redirect back on create/update; `422`/redirect-back on validation failure; `404` for an unknown id on edit/update. No JSON variant. 🟢
- **UI locks (not enforced server-side):** the id-1 row has no edit action; every row has delete disabled and there is no create button. These are grid-display gates, not authorization rules — the underlying resource routes still exist. 🟡 (`:59,66-69`)

---

## Consumed contracts (owned by other units)

`brands` reads/writes only the `brands` table through Eloquent; it calls no other unit's HTTP endpoint and no external service. 🟢

| Reads / writes | Owner unit | Purpose |
|----------------|------------|---------|
| `brands` rows (CRUD) | this unit | brand master data |

---

## Producer/consumer relationships

| This unit is… | Counterparty | Contract |
|---------------|--------------|----------|
| **Producer** | `products-catalog` | products reference a brand via the required `products.brand_id` FK; the product create/edit screen lists brands. 🟢 (`Brand.php:9-12`) |

---

## Cross-cutting contract notes

- **Scaffolded CRUD:** `store`/`update`/`destroy`/`show`/`create` are Encore\Admin `ModelForm` defaults; the domain contract is just `name`(required)+`description`. 🟢 (`:17,75-81`)
- **HTML/form, not JSON:** all responses are HTML pages or redirects. 🟢
- **Undeletable by design:** delete disabled on all rows because `products.brand_id` is a required FK. 🟢 (`:69`; `Brand.php:9-12`)
- **Protected default (id 1):** edit disabled on that row. 🟢 (`:66-68`)
- **Authorization:** authentication only; any admin may manage brands. 🟡 (ADR-0009)
- **No observability:** brand mutations emit no telemetry. 🔴 (`BrandController.php`, absence)
