Challenge the interface
Your Cancel button is disabled after cancellation. Someone calls transition from developer tools anyway. Should that succeed? If the rule exists only in the button's disabled state, the program has no reliable invariant.
An invariant is something that must remain true regardless of the interaction path. Here: cancelled orders cannot become editable drafts. Enforce it in the domain operation, and later enforce it again at the authoritative server boundary.
Design feedback and enforcement together
Disable or hide unavailable actions where appropriate, but give a visible reason. A disabled control may not receive keyboard focus, so do not hide the only explanation in its tooltip. The status text can explain which actions remain available.
Use native disabled on buttons for local interaction control. aria-disabled communicates a state but does not itself block a click handler. Do not treat it as an enforcement mechanism.
Repeated actions
There are two different situations: a second intentional command, and a retry of the same command after losing a response. Our local transition function rejects confirming an already confirmed order. A later server can return the original result for a recognized retry without performing the action again. That requires operation identity, not just a disabled button.
Build an experiment
Trigger the domain operation directly with a forbidden state and assert rejection. Then rapidly activate a UI action twice. While an operation is pending, guard against a second local request as well as disabling the button. Always restore a coherent pending/error state after failure.
Independent exercise
The user changes quantity after a confirmation request starts but before it finishes. Should the returned confirmation apply to the new draft? Write two possible policies and choose one.
Correction and reasoning
One policy locks editing while confirming; another allows edits but treats the response as confirmation of a captured earlier revision and explicitly reports the difference. For this course, lock editing during confirmation and re-enable it if confirmation fails. A response must never silently confirm values that were not sent.
Review
Explain the protection supplied by each layer: button state communicates availability, the handler prevents accidental duplicate local work, the domain transition enforces lifecycle rules, and the server will validate identity, revision and permission. None of these layers should pretend to replace the others.