routes/paypal.ts and routes/demo.ts were the pre-cart single-item checkout flow. Nothing has imported them since the cart flow landed: app.ts mounts only cartCheckout, the frontend calls /api/checkout/cart/*, and no test touches them. They duplicated PAYPAL_BASE, getAccessToken, and a second handler for the /webhooks/paypal mount. Also extract openCheckout() from /paypal/create and /demo/purchase in cartCheckout.ts, which repeated the same address-ownership check, cart lock, and checkouts/checkout_items inserts. It returns a discriminated union so callers keep control of the transaction and the response. Add CartItem/LockedCart interfaces, dropping the (it: any) casts. Note: paypal.ts was the only writer of items.reserved_until and items.paypal_order_id. Those columns are now write-dead; the schema is left alone for a separate migration. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>