# Brevo Contact Sync

## Objective

Add contacts to Brevo lists and keep their attributes and consent status current.

A sync that upserts contacts into configured Brevo lists with correctly typed attributes and preserved consent state.

## Before You Begin

This feature is being added to an application that already exists and already
works. Do not scaffold a new project, and do not assume a blank slate.

Inspect the codebase first and establish:

- The existing application structure and where code of this kind already lives.
- The framework and version in use.
- The existing design system — colours, spacing, typography, and component conventions.
- Existing UI components you can reuse instead of writing new ones.
- The existing database structure, if this feature needs to persist anything.
- The existing authentication and authorization system, if this feature is user-scoped.
- Dependencies already installed, so you don't add a library that duplicates one.
- The existing test setup and conventions.

Only start writing code once you understand the above. If the application
already implements part of this feature, extend it rather than replacing it.

## Implementation Instructions

1. Read the account's attribute definitions and their types when the mapping is configured, and validate each mapped app field against them, so a date, a number, and a text attribute are each sent in the form the account expects.
2. Treat list membership as additive by default. When updating a contact, send only the lists this sync is responsible for and leave every other membership alone rather than submitting a full replacement set.
3. Coalesce rapid changes to one contact into a single write using a short debounce keyed on the contact, so a burst of profile edits results in one update carrying the final state.
4. Read the contact's blocklist and unsubscribe status before writing, and skip any write that would re-enable sending. A new signup by a blocked address needs a fresh, recorded opt-in first.
5. Do not assume the account configuration you saw at setup still holds. Re-validate the destination lists and attributes before each run, and pause with a message naming what is missing rather than creating a replacement.

## UI and UX Requirements

Match the application's existing design system exactly. Reuse its components,
spacing, and typography. This feature should look like it was always there.

## Responsive Requirements

Works on mobile, tablet, and desktop. Touch targets are large enough to hit on a
phone, and nothing overflows horizontally at 320px.

## Accessibility Requirements

- Fully keyboard navigable.
- Correct semantic elements and ARIA roles.
- Visible focus states.
- Meets WCAG AA contrast.
- Dynamic changes are announced to screen readers.
- Respects prefers-reduced-motion.

## Edge Cases

- Attributes are typed, and a value sent in the wrong form is either rejected or silently coerced into something meaningless. Validate against the account's current attribute definitions rather than assuming everything is text.
- Blocked and unsubscribed contacts must never be re-enabled by a routine profile sync. Check the current state before writing, skip the write if it would resubscribe, and require a newly recorded opt-in to change that.
- A contact can belong to several lists, some of them managed by people outside the app. Submitting a complete list set on update silently removes the ones this sync does not know about, so only ever add or remove the lists it owns.
- Rapid profile changes generate a write per change and burn through the rate limit while applying states that are already stale. Debounce per contact and send the final state once.
- Lists get deleted and account configuration changes after the mapping was saved. Detect the missing destination, pause with a named error, and hold the queued contacts rather than sending them somewhere else.
- Job retries will resend the same update. Make writes idempotent on the contact's canonical email so a repeat is a no-op rather than a second list addition or a repeated welcome message.
- API credentials can be rotated or revoked at any time. Store them encrypted and server-side only, never in anything the browser receives, and mark the connection broken when they stop working.
- When the provider is down, the app's own signup or profile save must still complete and be confirmed. Queue the sync, show it as pending on the contact, and let an operator retry it.

## Testing

Exercise the feature end to end in the running application. Cover every edge case
above, then run the existing test suite and confirm nothing regressed.

## Acceptance Criteria

- [ ] Mapped attributes are validated against the account's current definitions and types before the mapping is saved.
- [ ] Blocked and unsubscribed contacts are never resubscribed without a newly recorded opt-in.
- [ ] Updates preserve list memberships this sync does not own.
- [ ] A burst of changes to one contact produces a single write carrying the final state.
- [ ] A deleted list or changed account configuration pauses the sync with a named error and holds queued work.
- [ ] Retried writes are idempotent and do not trigger repeated welcome messages.
- [ ] Credentials are stored encrypted server-side and never reach client-visible code.
- [ ] The feature matches the existing design system.
- [ ] No existing functionality is broken.

## Adaptation Rules

- Match the existing design system. Do not introduce a new colour palette,
  spacing scale, or component library.
- Reuse existing components and utilities wherever they fit.
- Follow the naming, file layout, and code style already present.
- Do not upgrade, replace, or remove existing dependencies to make this
  feature fit. Adapt the feature to the app, not the app to the feature.
- Do not break existing functionality. If a change is genuinely required in
  existing code, make the smallest one that works and say so.
- If something in these instructions conflicts with how the application is
  built, follow the application and explain the deviation.

## Final Verification

Before you report the work as done:

1. Re-read the acceptance criteria above and check each one against what you
   actually built.
2. Run the application and exercise the feature end to end.
3. Run the existing test suite and confirm you have broken nothing.
4. Check the feature on mobile, tablet, and desktop widths.
5. Check keyboard navigation and focus handling.
6. Summarize what changed: files added, files modified, and anything you
   deliberately did differently because of how this application is built.

If any acceptance criterion is unmet, fix it before reporting completion.
