# FAVO Auth + Purchase Idempotency + API Safety Overlay

This overlay:
- uses the canonical Favo\\Helpers\\Auth session in Authorization;
- passes transaction_uuid from the transaction controller;
- treats transaction_uuid as an idempotency key;
- uses a database transaction for purchase + loyalty + audit;
- handles concurrent duplicate-key races;
- does not reset DB, migrations, seed, or .env;
- removes password_hash from /api/v2/me.

Run `./bin/deploy-auth-idempotency` from the extracted package directory.
