Build & preview
development-unpackagedUnpackaged development viewUnavailableNot package-qualifiedNot embeddedUTC package timestampImmutable preview handoff
Qualified milestones include a SHA-verified launcher and isolated profile. Include the build ID and page name with feedback so the exact candidate is unambiguous.
Connections
Core modules
Constrained extension contract
Modules may declare routes, commands, capabilities, migrations, and supported clients. They cannot inject unrestricted navigation, execute arbitrary browser code, or bypass the scoped broker.
Access & security
Capability grants
Short-lived, audience-bound, actor-scoped, resource-scoped, and revocable by authority epoch.
implemented primitiveProvider secrets
Credentials remain server-side. No browser or module manifest can read them.
broker not connectedMutation receipts
Control, destructive, and financial commands require preflight and durable evidence.
adapter pendingProduction identity session broker
The donor and Unified foundations now exist on isolated candidate branches. They remain deliberately unselectable: the temporary staging bridge is the sole live authority until external qualification is complete and every caller migrates atomically.
explicit-per-deployment-selector → unified-opaque-bff-sessionDormant foundation
- donor-relying-party-candidateThe isolated Initrix candidate now provides one-time PKCE exchange, opaque RP sessions, signed webhook invalidation, explicit versioned authority links, configurable logout scope, durable provider revocation, and scoped read grants capped at 60 seconds. It remains disabled by default and undeployed.
- unified-session-store-candidateUnified now has a PostgreSQL contract for digest-only browser tokens, bounded rotation grace, idle and absolute expiry, encrypted upstream material, and a durable revocation outbox.
- browser-session-boundaryStart, callback, session, account switch, organization switch, and logout routes enforce safe returns, __Host cookies, CSRF, origin, fetch-metadata, immediate browser refresh, and server-render rotation deferral.
- single-authority-guardThe production factory assembles only under the exact production-rp selector in live mode and rejects every temporary Basic/static bridge input, while fixture Electron remains unable to receive production secrets.
- operator-and-cleanup-boundaryGuarded database migration, exact relying-party provisioning, canonical account writes, durable orphan cleanup, maintenance authentication, trusted-edge source partitions, and credential redaction are implemented and locally verified.
Activation gates
- provider-trust-proofA disposable real WorkOS tenant and token must prove one exact configured issuer, the HTTPS/TLS callback, webhook verification, and the selected custom-domain policy; issuer normalization or multiple accepted variants are prohibited.
- multi-tenant-provider-fixturesDisposable multi-user and multi-organization fixtures must cover login, account and organization switching, membership changes, revocation, expiry, and cross-tenant denial.
- trusted-edge-abuse-controlsThe source-partitioned limiter is implemented; the selected production edge, proxy CIDRs, forwarded-address behavior, and adversarial exhaustion isolation still require hosted proof.
- credential-redaction-boundaryThe redaction contract is implemented and locally tested; the selected hosted request logs, traces, breadcrumbs, and telemetry export still require canary proof.
- explicit-identity-migrationThe conflict-blocking migration and canonical writer are implemented; they must be run against an isolated production-shaped copy and the real conflict report must be resolved before production data is migrated.
- authority-link-policyThe strict versioned link and both logout modes are implemented; the actual WorkOS organization, Initrix Team, Lab workspace, role mappings, and logout policy still need owner approval and provisioning.
- hosted-secrets-and-storageDistinct least-privilege broker and Unified DSNs in the approved shared staging project, the RP client and maintenance secrets, independently owned keyrings, HTTPS origins, webhook, scheduler, backup, retention, and rotation operations must be provisioned and pass the mutual-denial boundary check.
- atomic-bridge-retirementEvery snapshot, page, API, redirect, and browser-state caller must migrate together before the Basic/static staging bridge can be deleted without parallel authority.