M3.4: guarded credential generations and publication account binding - #16
Conversation
…al source Verify content-addressed source transport, full Worker CI and no production credentials. No deployment or provider activation. The source-only preparer will be removed from the actual implementation candidate before integration.
…-account fencing Promote source tested in cloud run36879225624/job110426431012: full Worker CI including15 new connection runtime tests passed. Require the paired schema before managed snapshots; preserve stable CAS operation identity on response loss; reject mismatched queue destinations before new publication intent. Preserve generation/publishing disabled and all old provider boundaries. Paired native database and disconnect-race acceptance still required. No production deployment, secret export or social publication.
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
oneclickpostfactory-agent | 2b905b3 | Commit Preview URL Branch Preview URL |
Oct 01 2026, 02:53 PM |
AyobamiH
left a comment
There was a problem hiding this comment.
Exact worker head passed its own CI 36880484392 and authenticated readiness 36880484306. Paired app run 36965899241 then exercised this exact canonical consumer against isolated Supabase/PostgREST/PostgreSQL: 311 SQL assertions plus 14 connection-generation scenarios, including 16 refresh contenders, 16 publication contenders, response-loss replay, stale callback/refresh rejection, disconnect before identity/dispatch, account replacement review, unknown outcome no-resend, service-role raw-write denial, administrative drift, database restart and verified cleanup. Fixture provider calls only; live provider requests=0, production requests=0. Runtime/source flags remain default-off. This is implementation evidence, not live-provider acceptance.
AyobamiH
left a comment
There was a problem hiding this comment.
Exact-head Worker review: CI 36880484392 and authenticated-readiness 36880484306 passed. The paired application acceptance later exercised this exact Worker candidate against real isolated PostgREST/PostgreSQL through 14 connection/publication race scenarios: one fenced refresh writer, lost-response replay, disconnect vs refresh/callback, one provider POST under 16 competing publication requests, account-change review, preflight/dispatch disconnect fencing, unknown-outcome no-resend, service-role write denial, admin-drift ratchet and restart durability. The earlier paired failure was fixture cleanup after all 14 scenarios passed; application head 9a9f39b fixed cleanup without changing Worker source. Source flags remain default-off and no live provider effect is claimed.
Continue approved M3.4 from canonical main66b17ef; candidate2b905b3304e35c4366a37769a72200dd40e4e63e. The publishing fork and unrelated local post-once are untouched.
Implements complete-schema-gated credential snapshots, request-scoped connection sessions, fenced token persistence for existing X/Threads/LinkedIn callbacks, exact queued-account preflight, same-operation response-loss replay, explicit account verification before dispatch and conditional effect-free readiness. Managed tenants without an OpenAI key cannot fall back to the global key. The paired private app migrations add actual CAS/disconnect/callback and dispatch ownership checks. Both source and runtime flags remain default-off; legacy disabled publishers remain disabled.
Cloud preparation36879225624/job110426431012 passed full Worker CI including15 new runtime regressions and executable smoke. The exact tested plaintext file blobs were promoted; the one-off source preparer is absent from this tree. No lockfile, original secret, production deployment or external provider effect.
This PR is deliberately pending the paired private app/schema native integration, not merely these unit tests. Tests must exercise real PostgREST/PostgreSQL against this consumer, stale refresh/callback/disconnect, queued account replacement, publication boundaries, unknown response, concurrency and restart. Full M3 acceptance also requires actual Stripe sandbox/operational readiness and coherent rollout. Disconnect blocks a dispatch only when it wins before database dispatch authorisation; it cannot unsend an already authorised remote request. Read identity is not proof of all publishing permissions.
Contract: docs/CONNECTION_GENERATIONS_V1.md. Cross-repository shared protocol files must be byte-identical and tested together.