Skip to content

fix: harden two-App identity persistence contract #955

Description

@sabbour

Part of #938.\n\nHarden the merged two-App persistence foundation before #941, #942, and #943: add an external-safe MCP/browser authorization transaction identifier bound to app kind and Entra subject; add cross-provider lifecycle delivery replay claims; define stable credential-version grant semantics; and correct the webhook replay contract to delivery-id uniqueness plus HMAC validation without an unenforceable GitHub delivery-age assertion.\n\nDependencies: #954\nBlocks: #941, #942, #943

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    squad:tankAssigned to Tank (Backend Engineer)type:bugSomething broken

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions