Add private Business push delivery and provider receipts - #1010
Closed
sridharkalaibala wants to merge 2 commits into
Closed
sridharkalaibala wants to merge 2 commits into
sridharkalaibala wants to merge 2 commits into
Conversation
This was referenced Sep 28, 2026
Contributor
Author
|
The complete Business companion stack, including this change, is integrated into develop through #1023. All checks, including CodeQL, passed before merge. Closing this superseded stacked PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Business sessions can opt a phone into generic push alerts for new Inbox entries. Registrations are private and session-bound; delivery rechecks current session/password generation, branch membership, financial permission and notification preferences. The worker uses durable event/device records, retry delays and provider receipts. A delayed invalid-device receipt cannot delete a newer registration.
The fixed Expo transport sends no sales amounts, account credentials, URLs or approval commands. Stable collapse/tag IDs reduce visible duplicates after ambiguous network failures. Provider acceptance is recorded separately from user/device delivery; no exactly-once promise is made. Delivery stays disabled unless the owning deployment configures its project and secret access token. Community operators must not receive Posnic's project credential; an official-app relay is still pending.
Local validation: 12 access/reporting/notification-route integration tests, five notification integration tests, five push integration tests, two transport tests, two worker tests, and 24 README/sync checks pass. Changed services pass lint and attribution. API docs report 730 endpoints. Provider calls are mocked; no actual push was sent and no CI expansion was added.
Stacks on #1009. Native app registration is in the companion mobile push branch. Production credentials, physical devices and Community relay qualification remain required.