List age-verification attestations
Reads the durable age-verification compliance trail (justificatif de contrôle d’âge) — the append-only legal record that a restricted-item check was performed. Reach for this to produce the evidence a regulator asks for, or to audit a given transaction or operator. Every facet is OPTIONAL and combined as AND: transactionRef (one sale), operatorId (one cashier), outcome (pass/block/needs_check), and the inclusive instant range from/to (ISO-8601). With no filter it returns the WHOLE trail, ordered newest-first. The rows carry NO customer identity — by construction the trail cannot hold a date of birth, name or document number. There is deliberately no store filter (the row has no store column). Gating: the router rides the till scope pos.checkout.operate.
Authorizations
Authorization: Bearer <token>. Accepts EITHER a Keycloak access token (scopes-in-token) OR an opaque POS session token; both resolve to the same pos.* scope vocabulary the route guards enforce.
Query Parameters
Filter to the check(s) recorded for one transaction/ticket reference.
1Filter to the checks a single operator (cashier) recorded.
1Filter to one decision: pass, block or needs_check.
pass, block, needs_check Inclusive lower bound on the instant (at >= from).
1Inclusive upper bound on the instant (at <= to).
1Response
The matching attestations, newest first (empty array when none match).
^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$pass, block, needs_check 
