feat: maintain verified sessions for protected conversation files - #147
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requests fresh identity verification for projects requiring authenticated files, transports the short-lived file session to Messenger, refreshes before expiry without postponement by ordinary session polling, and revokes on logout. Emailed file links resume the authorized conversation after the host application verifies its user.
Tokens are not put in file URLs. Includes identity-change isolation and partial-session-update regressions. Source changes only: generated release bundles and already published version assets are excluded; no package publishing/version bump.
Validation: 277 tests across 19 suites and webpack build pass. Existing bundle-size warnings remain.
This is a coordinated, deployment-gated change. No production deployment, bucket provisioning, package publication, or legacy-file migration/purge is included. Read
AUTHENTICATED_FILES.mdfor deployment order, compatibility requirements and staging checks. Keep the project opt-in disabled until the companion services and supported clients are deployed and verified.Companion PRs: