Skip to content

M3.4: guarded credential generations and publication account binding - #16

Merged
AyobamiH merged 2 commits into
mainfrom
codex/m3-connections-20261001
Oct 2, 2026
Merged

AyobamiH merged 2 commits into
mainfrom
codex/m3-connections-20261001

Conversation

@AyobamiH

@AyobamiH AyobamiH commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Continue approved M3.4 from canonical main66b17ef; candidate2b905b3304e35c4366a37769a72200dd40e4e63e. The publishing fork and unrelated local post-once are untouched.

Implements complete-schema-gated credential snapshots, request-scoped connection sessions, fenced token persistence for existing X/Threads/LinkedIn callbacks, exact queued-account preflight, same-operation response-loss replay, explicit account verification before dispatch and conditional effect-free readiness. Managed tenants without an OpenAI key cannot fall back to the global key. The paired private app migrations add actual CAS/disconnect/callback and dispatch ownership checks. Both source and runtime flags remain default-off; legacy disabled publishers remain disabled.

Cloud preparation36879225624/job110426431012 passed full Worker CI including15 new runtime regressions and executable smoke. The exact tested plaintext file blobs were promoted; the one-off source preparer is absent from this tree. No lockfile, original secret, production deployment or external provider effect.

This PR is deliberately pending the paired private app/schema native integration, not merely these unit tests. Tests must exercise real PostgREST/PostgreSQL against this consumer, stale refresh/callback/disconnect, queued account replacement, publication boundaries, unknown response, concurrency and restart. Full M3 acceptance also requires actual Stripe sandbox/operational readiness and coherent rollout. Disconnect blocks a dispatch only when it wins before database dispatch authorisation; it cannot unsend an already authorised remote request. Read identity is not proof of all publishing permissions.

Contract: docs/CONNECTION_GENERATIONS_V1.md. Cross-repository shared protocol files must be byte-identical and tested together.

…al source

Verify content-addressed source transport, full Worker CI and no production
credentials. No deployment or provider activation. The source-only preparer
will be removed from the actual implementation candidate before integration.
…-account fencing

Promote source tested in cloud run36879225624/job110426431012: full Worker
CI including15 new connection runtime tests passed. Require the paired schema
before managed snapshots; preserve stable CAS operation identity on response
loss; reject mismatched queue destinations before new publication intent.
Preserve generation/publishing disabled and all old provider boundaries.
Paired native database and disconnect-race acceptance still required.
No production deployment, secret export or social publication.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
oneclickpostfactory-agent 2b905b3 Commit Preview URL

Branch Preview URL
Oct 01 2026, 02:53 PM

@AyobamiH AyobamiH left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact worker head passed its own CI 36880484392 and authenticated readiness 36880484306. Paired app run 36965899241 then exercised this exact canonical consumer against isolated Supabase/PostgREST/PostgreSQL: 311 SQL assertions plus 14 connection-generation scenarios, including 16 refresh contenders, 16 publication contenders, response-loss replay, stale callback/refresh rejection, disconnect before identity/dispatch, account replacement review, unknown outcome no-resend, service-role raw-write denial, administrative drift, database restart and verified cleanup. Fixture provider calls only; live provider requests=0, production requests=0. Runtime/source flags remain default-off. This is implementation evidence, not live-provider acceptance.

@AyobamiH
AyobamiH marked this pull request as ready for review October 2, 2026 04:51
@AyobamiH
AyobamiH merged commit 4081932 into main Oct 2, 2026
4 checks passed

@AyobamiH AyobamiH left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head Worker review: CI 36880484392 and authenticated-readiness 36880484306 passed. The paired application acceptance later exercised this exact Worker candidate against real isolated PostgREST/PostgreSQL through 14 connection/publication race scenarios: one fenced refresh writer, lost-response replay, disconnect vs refresh/callback, one provider POST under 16 competing publication requests, account-change review, preflight/dispatch disconnect fencing, unknown-outcome no-resend, service-role write denial, admin-drift ratchet and restart durability. The earlier paired failure was fixture cleanup after all 14 scenarios passed; application head 9a9f39b fixed cleanup without changing Worker source. Source flags remain default-off and no live provider effect is claimed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant