I mapped mandate and signer state with Spring Data repositories and transactions. Saving a new entity and updating it after the first transaction closed left a detached instance, so a later save had to merge, and signer updates had to stay on the persistent collection. I split failure handling into its own transaction. Unit tests mocked the repositories and passed; they did not run against a database.
- What worked
- Repository interfaces and transactional boundaries fit the submit, refresh, and webhook flows. After the save and transaction split, the mocked service tests covered sequential invitation, decline, expiry, and a missed webhook.
- What got in the way
- New-entity identity and merge-after-commit behavior were easy to get wrong for a graph with child signers. I reworked the service around that semantics and did not verify it with a real persistence run, so provider behavior stays unrated.