The first cloud slice: accounts, sites and membership, which do not wait for the KM43 key work (origin89hq/km43#128, #129). Design and decisions: origin89hq/internal-research#1.
Scope
- Tokens. Verify WorkOS access tokens (JWT) against the WorkOS JWKS. Store our own
user_id, and keep the provider's issuer and subject as an alias, never a bare sub.
- Model. Users, sites (named by the owner), controllers by
device_id with an ownership generation, and memberships (owner, admin). History and access belong to a generation, never to a device_id alone.
- Linking. Link a controller the phone is already enrolled with to a site. The request carries
device_id, epoch and a display name; it never carries the printed secret or a client key. Membership grants no controller access; the controller stays the authority.
- Account deletion, required in-app by App Store guideline 5.1.1(v). The server deletes the WorkOS user with the secret API key and removes memberships. It does not touch controller enrolments.
- API contract. A versioned contract package that the apps pin, following the Buddy pattern.
Out of scope
Invites, the readings store and MQTT, which wait for km43#129.
Repository setup still open
- Tooling and a
Checks workflow land with the first code. When they do, add its job as a required status check.
main has no branch protection or ruleset yet: GitHub refuses both on a private repository in a free organization. Either make the repository public, as the other service repos are, or upgrade the organization, then apply the buddy/website protection: PR required, linear history, conversation resolution, admins included.
Acceptance
Tests for token verification (valid, expired, wrong issuer or audience, unknown key), linking (success, duplicate, another owner's generation), and deletion; the contract published and consumed by origin89hq/apps.
The first cloud slice: accounts, sites and membership, which do not wait for the KM43 key work (origin89hq/km43#128, #129). Design and decisions: origin89hq/internal-research#1.
Scope
user_id, and keep the provider's issuer and subject as an alias, never a baresub.device_idwith an ownership generation, and memberships (owner,admin). History and access belong to a generation, never to adevice_idalone.device_id, epoch and a display name; it never carries the printed secret or a client key. Membership grants no controller access; the controller stays the authority.Out of scope
Invites, the readings store and MQTT, which wait for km43#129.
Repository setup still open
Checksworkflow land with the first code. When they do, add its job as a required status check.mainhas no branch protection or ruleset yet: GitHub refuses both on a private repository in a free organization. Either make the repository public, as the other service repos are, or upgrade the organization, then apply the buddy/website protection: PR required, linear history, conversation resolution, admins included.Acceptance
Tests for token verification (valid, expired, wrong issuer or audience, unknown key), linking (success, duplicate, another owner's generation), and deletion; the contract published and consumed by origin89hq/apps.