Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
136 commits
Select commit Hold shift + click to select a range
ef9feff
feat: add Chat v2 account authority operations
replghost Sep 9, 2026
da72d30
fix: align Chat client examples and catalog test
replghost Sep 9, 2026
36b0dbb
feat(chat): add explicit context-bound cipher suite
replghost Sep 9, 2026
035f12e
fix(codegen): update Chat wire schema golden
replghost Sep 10, 2026
c47f1b6
Merge branch 'feat/pvm-app-runtime' into feat/chat-v2-product-authority
replghost Sep 10, 2026
4ccb114
feat: add dedicated Chat authority permission
replghost Sep 10, 2026
a0681e1
chore: regenerate Chat authority artifacts
replghost Sep 10, 2026
4388850
fix(chat): forward product statement proofs over SSO
replghost Sep 11, 2026
e6e31b5
fix(chat): sign first-contact proofs without message framing
replghost Sep 12, 2026
7d4ca68
fix(identity): register Chat-capable X25519 keys
replghost Sep 12, 2026
da64a51
Integrate browser wallet host support above Chat authority
replghost Sep 12, 2026
a217452
Merge commit 'e3a37f0be703715dbdfb39cc68e7b02e6c19acd4' into integrat…
replghost Sep 14, 2026
d0ed5a1
Merge commit '810aa11e' into integrate/chat-receive
replghost Sep 14, 2026
ccf2fc9
feat(chat): authenticate incoming product-device requests
replghost Sep 14, 2026
8ff4a85
Merge branch 'integrate/local-wallet-native-base' into integrate/chat…
replghost Sep 14, 2026
8911041
fix(chat): inherit persistent username confirmation monitoring
replghost Sep 15, 2026
07a5fc8
fix: align allowance helpers with wasm target boundaries
replghost Sep 15, 2026
4bdc938
Merge branch 'fix/wasm-allowance-boundary-540' into fix/chat-authorit…
replghost Sep 15, 2026
fd612bc
Merge branch 'fix/wasm-allowance-boundary-540' into fix/chat-authorit…
replghost Sep 15, 2026
65d8080
fix(chat): enforce dedicated authority on local product calls
replghost Sep 15, 2026
88bb941
Merge branch 'fix/wasm-allowance-boundary-540' into fix/chat-authorit…
replghost Sep 15, 2026
ddccbac
Merge branch 'fix/wasm-allowance-boundary-540' into fix/chat-authorit…
replghost Sep 15, 2026
4180a21
Merge SDK 0.16 into Chat authority and allocate its scoped method add…
replghost Sep 15, 2026
00f1499
Merge branch 'fix/wasm-allowance-boundary-540' into fix/chat-authorit…
replghost Sep 15, 2026
2d43b93
Format the SDK 0.16 Chat migration
replghost Sep 15, 2026
eeec65d
Merge branch 'fix/wasm-allowance-boundary-540' into fix/chat-authorit…
replghost Sep 15, 2026
15d9861
Complete Chat codec two integration coverage and migration notes
replghost Sep 15, 2026
4881067
Merge branch 'fix/wasm-allowance-boundary-540' into fix/chat-authorit…
replghost Sep 15, 2026
726c697
fix(ios): route dedicated Chat authority through permission guard
replghost Sep 15, 2026
57bbf8d
Merge commit 'a5c3f3f2' into fix/chat-authority-review-709
replghost Sep 15, 2026
656698d
Merge commit '7260aabd' into fix/chat-authority-review-709
replghost Sep 15, 2026
91e55b5
style: format Chat changeset
replghost Sep 15, 2026
01c1fd5
Merge commit '5c04f3afa5ce2004d6ec3e37603289321a329a99' into fix/chat…
replghost Sep 15, 2026
5bfe42d
fix(ios): fund selected product statement-store accounts without expo…
replghost Sep 16, 2026
a34218f
fix(ios): separate permission confirmation dispatch
replghost Sep 16, 2026
d956dda
Persist scoped statement allowance grants without approving silent in…
replghost Sep 16, 2026
0d70243
Keep native renewal ledger storage out of browser builds
replghost Sep 16, 2026
d0c157a
test: isolate method-keyed RPC fixtures across reconnects
replghost Sep 16, 2026
8372260
Merge remote-tracking branch 'origin/feat/pvm-app-runtime' into refre…
replghost Sep 17, 2026
05d8cb8
fix(wasm): gate native renewal inspection
replghost Sep 17, 2026
49f7ec8
Merge remote-tracking branch 'origin/feat/pvm-app-runtime' into refre…
replghost Sep 17, 2026
e55f78a
Merge remote-tracking branch 'origin/feat/pvm-app-runtime' into refre…
replghost Sep 17, 2026
027feac
Merge runtime wallet claim progress into Chat authority
replghost Sep 17, 2026
0926e88
Merge remote-tracking branch 'origin/feat/pvm-app-runtime' into refre…
replghost Sep 17, 2026
97ea37b
feat(chat): move native Chat and main-purse payments into shared Host
replghost Sep 21, 2026
4a8b867
fix(chat): include complete crypto sources in the shared Host workspace
replghost Sep 22, 2026
e4af1e6
build(chat): lock dependency resolution for reproducible Host generation
replghost Sep 22, 2026
837bd4f
docs(chat): record shared main-purse authority release notes
replghost Sep 22, 2026
8de303f
feat(chat): use native iOS custody and product-owned messaging
replghost Sep 23, 2026
5704252
fix(chat): address second review of Chat v2 product authority
replghost Sep 23, 2026
fc86c56
chore: merge refreshed feat/pvm-app-runtime into feat/chat-v2-product…
replghost Sep 23, 2026
a9d055a
fix: restore chat v2 branch checks
replghost Sep 23, 2026
6f1563b
Merge remote-tracking branch 'origin/feat/chat-v2-product-authority' …
replghost Sep 23, 2026
e4424be
fix(truapi): ignore late responses on known method pairs
replghost Sep 23, 2026
e6822d2
fix(js): reconcile the worker host surface after the main merge
replghost Sep 23, 2026
cf0221a
Merge commit '6f1563b7e' into fix/pr709-review-2
replghost Sep 23, 2026
6853dcf
Merge remote-tracking branch 'origin/feat/chat-v2-product-authority' …
replghost Sep 23, 2026
9f6a123
fix: reconcile chat branch with updated runtime
replghost Sep 23, 2026
b626f90
Merge remote-tracking branch 'origin/feat/chat-v2-product-authority' …
replghost Sep 23, 2026
2d8a629
fix: align browser host integration
replghost Sep 23, 2026
8f301bb
Merge remote-tracking branch 'origin/feat/pvm-app-runtime' into feat/…
replghost Sep 23, 2026
c3f9adb
Merge remote-tracking branch 'origin/feat/chat-v2-product-authority' …
replghost Sep 23, 2026
d3dec53
test(chat): build the refused product context for the SSO attestation…
replghost Sep 23, 2026
4c73446
fix: restore cross-platform host checks
replghost Sep 23, 2026
50e27db
Merge remote-tracking branch 'origin/feat/chat-v2-product-authority' …
replghost Sep 23, 2026
f296c55
test: update native custody key indices
replghost Sep 24, 2026
c5c39cf
fix: clear iOS warning ratchet
replghost Sep 24, 2026
0b5c741
fix(runtime): bound the host callbacks on own-account resolution
replghost Sep 24, 2026
6f7958b
Merge remote-tracking branch 'origin/feat/pvm-app-runtime' into HEAD
replghost Sep 24, 2026
bd060cc
Merge feat/pvm-app-runtime (wallet allowance inspection) into feat/ch…
replghost Sep 25, 2026
2fd97b2
fix(allowance): compile the renewal ledger reader for the browser sig…
replghost Sep 25, 2026
131c17e
Merge feat/pvm-app-runtime (#540): no-std import and clippy fix
replghost Sep 27, 2026
1284d03
Merge refreshed feat/pvm-app-runtime (SDK 0.21) into feat/chat-v2-pro…
replghost Sep 27, 2026
55713ed
fix(ios): Chat authority always prompts, even for a trusted product
replghost Sep 27, 2026
07ac76e
fix(chat): release the wallet lease before answering a payment call
replghost Sep 27, 2026
8ba4092
fix(sso): give the unreleased Chat v2 messages their own index block
replghost Sep 28, 2026
5e6da34
Merge updated host base
replghost Sep 28, 2026
a5502aa
Merge light-client CLI base into feat/chat-v2-product-authority
replghost Sep 29, 2026
2526446
Merge current host base into Chat v2 product authority
replghost Sep 29, 2026
74423b3
Merge host packaging and allocation fixes into Chat stack
replghost Sep 29, 2026
979dda2
fix(chat): migrate compiler boundaries to unified runtime
replghost Sep 29, 2026
1772ce9
Merge commit '6898a7f95' into HEAD
replghost Sep 29, 2026
3820751
Align Chat runtime features and authority with unified core
replghost Sep 29, 2026
4c52459
Complete unified Chat storage and license migration
replghost Sep 29, 2026
ba19476
Merge commit '522e14465' into HEAD
replghost Sep 29, 2026
d40c693
Merge commit 'f9d72df5e' into HEAD
replghost Sep 29, 2026
46c7c01
Merge commit 'e73014d21dcab5064b3484a9d599310fa523ef2d' into HEAD
replghost Sep 29, 2026
e2accca
test(codegen): qualify generated contracts without source snapshots
replghost Sep 29, 2026
64d18eb
fix(ios): preserve Chat coinage schema across main integration
replghost Sep 29, 2026
a36962b
fix(chat): keep attachment capabilities private and restore wire checks
replghost Sep 29, 2026
179fc93
fix(coinage): settle claims whose source was spent elsewhere
replghost Sep 29, 2026
2c38acc
fix(chat): bound Chat records per peer and honour allow-once for the …
replghost Sep 29, 2026
a7c0430
Merge branch 'fix/pr709-r3-topup' into fix/pr709-review-3
replghost Sep 29, 2026
f4d39d8
chore: update dotli PolkaVM runtime setting
replghost Sep 29, 2026
8b73633
fix(ios): review Chat payments outside the serial coinage queue
replghost Sep 29, 2026
acc2487
Merge branch 'fix/pr709-r3-ios' into fix/pr709-review-3
replghost Sep 29, 2026
4357942
Merge remote-tracking branch 'origin/feat/chat-v2-product-authority' …
replghost Sep 29, 2026
59c0d3a
chore: update dotli runtime opt-in coverage
replghost Sep 29, 2026
4c9cc84
chore: update dotli stacked runtime setting
replghost Sep 29, 2026
18e4535
Merge feat/pvm-app-runtime into feat/chat-v2-product-authority
replghost Sep 29, 2026
68ea768
fix(chat): address review of the Chat authority fixes
replghost Sep 29, 2026
3855ff1
fix(ios): share one payment review per operation until its decision i…
replghost Sep 29, 2026
3fe0aaa
fix(chat): bound Chat records per peer without evicting them
replghost Sep 29, 2026
0704c74
Merge branch 'fix/pr709-r3-ios' into fix/pr709-review-3
replghost Sep 29, 2026
c1d982c
Merge commit 'e4f657dfe' into HEAD
replghost Sep 29, 2026
9e21d86
Merge remote-tracking branch 'origin/feat/chat-v2-product-authority' …
replghost Sep 29, 2026
b17687c
Merge remote-tracking branch 'origin/feat/pvm-app-runtime' into HEAD
replghost Sep 29, 2026
c592acb
feat(chat): expose authenticated host-private contacts directory
replghost Sep 30, 2026
0eccd80
fix(contacts): resolve host adapter installed after runtime creation
replghost Sep 30, 2026
f8cd4e2
docs(chat): record top-up settlement evidence and its per-installatio…
replghost Sep 30, 2026
aab15ca
Merge remote-tracking branch 'origin/feat/chat-v2-product-authority' …
replghost Sep 30, 2026
437a46c
fix(ci): retain iOS test failure diagnostics
replghost Sep 29, 2026
89d9f34
Merge commit 'd155c1474f8dce3bdca63637acee078afc84574b' into HEAD
replghost Sep 30, 2026
4b241e8
Merge commit '953519aa65f02412ae487ce2356d04ed56b5622d' into HEAD
replghost Sep 30, 2026
2cb2412
Merge refreshed PolkaVM base into Chat with SQLite and named sessions
replghost Oct 1, 2026
daf0ff5
Merge commit '1709e630c87d336e30632799f587d0bd09e1a80d' into HEAD
replghost Oct 1, 2026
21c870c
Merge commit '9dcf66544e02b3bb3994e05f3a1400738f742331' into HEAD
replghost Oct 1, 2026
e6c6ed3
Normalize named-session integration formatting
replghost Oct 1, 2026
08bddf3
test: complete Chat runtime configuration migration
replghost Oct 1, 2026
c1e38d3
Merge commit 'ec91cdc01daa7ff57af61cb1f943d28a1036c9c6' into HEAD
replghost Oct 1, 2026
6d97c79
Merge commit 'e0a8d59a07e72c4c7f36e6bab6c1db34c06d35dc' into HEAD
replghost Oct 1, 2026
726ef76
Merge commit 'a572456b90dc6932476f2fb5a71985fbe9fcbd84' into HEAD
replghost Oct 2, 2026
4100ceb
Merge feat/pvm-app-runtime into feat/chat-v2-product-authority
replghost Oct 2, 2026
5bbad3f
fix(test-host): withhold product statement allowances after runtime sync
replghost Oct 2, 2026
4dcc4de
docs(test-host): document indexed statement resource withholding
replghost Oct 2, 2026
e521d81
Merge runtime subtree synchronization into feat/chat-v2-product-autho…
replghost Oct 2, 2026
87a085b
test(signing-host): await Chat product state cleanup
replghost Oct 2, 2026
0c9415e
Merge runtime snapshot fixture correction into feat/chat-v2-product-a…
replghost Oct 2, 2026
f702177
Merge frozen runtime main update into feat/chat-v2-product-authority
replghost Oct 2, 2026
b5c4c0e
Merge host locale timestamp conversion into Chat
replghost Oct 2, 2026
83c288e
Merge locale binding corrections into Chat
replghost Oct 2, 2026
01c16a0
Merge explicit API version binding fix into Chat
replghost Oct 2, 2026
7f07aeb
chore(codegen): regenerate Chat locale client catalog
replghost Oct 2, 2026
ceea3cd
Merge generator fixture compile fix into Chat
replghost Oct 2, 2026
80ba885
merge: forward pinned-nightly Locale formatting into native 709
replghost Oct 2, 2026
901a3e7
Merge qualified runtime updates from #540 into #709
replghost Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
89 changes: 89 additions & 0 deletions .changeset/chat-product-authority.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
---
"@parity/truapi-host": minor
---

Add product-scoped Chat v2 authority with dedicated Chat authorization, separate from username disclosure. Apply the
boundary to local and SSO sessions, expose it in the iOS permission flow, and avoid cloning secret-bearing pairing
results.

Use the unified runtime's native UniFFI gates and shared clock, dotNS discovery and runtime view-response decoding
for Chat and Coinage without changing product authorization or payment review policy.

Keep renewal-ledger mutation native-only and use the chain metadata's extension version for Coinage extrinsics.
Trusted products still honor explicit network-permission denials.

Align Android's durable core store with suspend callbacks while retaining serialized, committed writes.
Carry the existing scoped AGPL license exception onto the unified runtime crate.

Support keyless Statement Store allowances for a selected product account in the native signing host.

Replace raw guest Chat crypto with a narrow authenticated Host boundary on account method 12; retire method 11,
including over SSO. Products own ordinary Chat, subscriptions, transport and ACKs. Keep identity/device keys and
outgoing payment secrets private; require trusted per-payment review for main-purse debits. Incoming bearer keys may
enter encrypted product recovery storage and are imported through generic `payment.top_up(Coins)`. Retain private nested
HOP recovery and resumable file/image/video preparation with trusted selection/export. The combined signing runtime
includes AGPL-3.0-only code; retain the included provenance, licenses and exact Corresponding Source.

Include the complete native Chat wire, attachment and cryptography implementation as the source-owned `truapi-chat-v2`
crate, with upstream provenance and licensing. Remove the release dependency on unpublished local Cargo overrides.

Align Coinage keys with current iOS MAIN_PURSE/page-0 derivations, including the soft coin item junction. Keep complete
exported coin secrets stable for durable payment replay. Authenticate the new purse layout through snapshot version 3;
reject legacy `//pps` snapshots without discarding pending wallet state. Inject native wallet custody at runtime
construction: reference iOS supplies its existing Coinage service adapter; browser/CLI use Rust when none is registered.

Read origin-specific free Coinage unload-token limits from the runtime view at the finalized planning snapshot, rather
than a removed metadata constant. Preserve committed payment ciphertext and native request IDs when renewing statement
expiry. Statement submission, backpressure and ordinary retry queues belong to the product.

Accept validated native push-token metadata without discarding the surrounding iOS acceptance batch. Authenticate native
identity/device ACK direction and reject own-signer ciphertext reflections before opening private payloads.

Use request/response V2 and encrypted SSO V3; reject the former actor request rather than returning fake compatibility
responses. Provide bounded replayable HOP and public-state pages with original native IDs. Transfer legacy ordinary
history, pending ciphertext and caller/native ID mappings only after explicit durable migration acknowledgment.

Import incoming keys through the selected owner's durable custody: the encrypted Rust main-purse WAL or native
IncomingPaymentService. Recover owner-bound accepted imports after unlock independently of Chat grants or a running
guest. Expose trusted denomination metadata without opening a wallet allocator: native memo totals and top-up minimums
are raw u128 chain units, while Chat cards use checked native cents. Preserve exact import amounts on retries and do not
report ambiguous or underfunded claims as fully cleared.

Allow outgoing payments once an active, keyed peer device acknowledges the legacy-device revocation update. Encrypt only
for acknowledged devices and reject payment acknowledgments from devices excluded from the committed envelope. Reset
eligibility after authenticated roster changes while preserving payment identity and exact memo custody through
rewrapping and retries.

Document the method 12 request/response, compatibility, custody, device eligibility, and per-spend consent contract in
the unnumbered [draft native Chat/main-purse RFC](../docs/rfcs/native-chat-main-purse.md), submitted for review with
this implementation. Clarify its relationship to [RFC 0017](../docs/rfcs/0017-coinage-payment.md), including the
distinct integer amount/asset contracts and the absence of general purse APIs or a Chat balance query. Keep the native
Rust-purse storage guard: the adapter does not permit competing allocators or automatic fallback. This specification
link does not assert RFC approval, publication, native iOS compilation, or cross-platform qualification.

Mark native Chat payments as transitional pending RFC 0017 receivables, encrypted cheques, and deposits using the main
purse. Preserve current native-peer payments and pending custody without claiming RFC 0017 support or introducing a
separate Chat allocator. The Host no longer runs ordinary Chat receivers when the product is closed.

Generate current request/success envelopes with compatible older domain-error envelopes instead of silently omitting the
method. Preserve wire discriminants after retiring a version prefix, and exercise the generated client against V2 Chat
responses and V1 errors.

Add an optional Host-private native-wallet dependency, fixed at runtime construction. Absence uses Rust by default;
registered native failures never switch owners. Remove the explicit wallet-selection callback and enum. Route reference
iOS outgoing payments, incoming imports and status through the coordinator's existing Coinage service. Retain native
outgoing custody atomically with native transaction registration before exposing a memo to trusted Host crypto, then
track ciphertext acceptance, peer delivery and finality separately. Preserve per-payment and privacy review,
source/idempotency bindings, activation fencing and authoritative native wallet balance. Native callback infrastructure
errors are sanitized; product callback overrides cannot replace the runtime-wide wallet owner.

Bind native incoming receipts to wallet root, chain and asset instance in the additive Core Data schema upgrade.
Preserve unowned pre-upgrade incoming rows and source secrets without automatically claiming them into the current
wallet. Pending imports without provable ownership require explicit ownership recovery before resumption.

Add a host-private native Chat contacts snapshot for signing hosts, with authenticated readiness, authorization,
wallet/network isolation, encrypted-state restoration, identity deduplication and conservative verified names. Persist
the native product index when actors open; historical unindexed products need one open on the upgraded host. Fence reads
against actor commits and session changes, invalidate contact handles on trusted mutations, and reject late worker
responses. Preserve provider-scoped Contacts UI callbacks without replacing the shared owner directory. Pairing hosts
remain unsupported; no product wire or SSO directory API is added.
4 changes: 4 additions & 0 deletions .changeset/olive-schools-shave.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ the statement-proof and preimage paths ask for without requesting an
allocation. A changed permission answer reaches the core, and product storage
is readable under the name `@parity/host-api-test-sdk` gives it.

`ProductStatementStoreAllowance` withholds product-account statement
allowances at every derivation index without withholding the separate
`StatementStoreAllowance` resource.

Surface a migrating suite has to match:

- `PermissionLogEntry` carries `decision` and `timestamp` as required fields,
Expand Down
7 changes: 7 additions & 0 deletions .changeset/pvm-host-runtime-authority.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,10 @@ requests its shared or static library artifacts.
Build each iOS XCFramework slice with its own `cargo rustc` invocation.
Explicit static-library output cannot be combined with multiple target triples
in one invocation.

Qualify callback contracts through executable codec and WASM checks rather than
full-source declaration snapshots, while retaining deterministic code generation.

Preserve incoming-payment ownership and native Coinage ledger records when
migrating either the historical Chat store or current main's iOS store to the
combined model. Retain both historical model variants for migration detection.
24 changes: 19 additions & 5 deletions .github/workflows/ios-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -101,8 +101,8 @@ env:
# DEBUG MODE: Set to 'true' to enable enhanced debugging for build failures
# What it does:
# - Enables verbose xcodebuild logging
# - Collects and uploads build artifacts (logs, test results)
# - Continues build even on failures to gather maximum information
# - Collects and uploads build artifacts
# Test results and diagnostics are uploaded regardless of this setting.
DEBUG_CI: false

jobs:
Expand Down Expand Up @@ -517,13 +517,27 @@ jobs:
bundle exec fastlane run_unit_tests
fi

# Upload test artifacts for debugging - only when DEBUG_CI is enabled
- name: Export test diagnostics
if: always()
working-directory: hosts/ios
run: |
set -euo pipefail
result="fastlane/test_output/polkadot-app.xcresult"
if [[ -d "$result" ]]; then
xcrun xcresulttool get test-results summary --path "$result"
xcrun xcresulttool get test-results tests --path "$result"
xcrun xcresulttool export diagnostics --path "$result" \
--output-path fastlane/test_output/diagnostics
fi

- name: Upload test artifacts
if: env.DEBUG_CI == 'true' && (failure() || success())
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: test-artifacts-${{ github.run_number }}
name: test-artifacts-${{ github.run_id }}-${{ github.run_attempt }}
path: |
hosts/ios/fastlane/test_output/
hosts/ios/fastlane/build_logs/
~/Library/Logs/DiagnosticReports/*.ips
~/Library/Logs/DiagnosticReports/*.crash
retention-days: 3
21 changes: 19 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,11 +14,19 @@ generated from [Conventional Commits](https://www.conventionalcommits.org/).
deadlines, multi-touch input, and image clipboard output (#540)
- let browser signing hosts request personhood-backed Statement Store
allowances for products instead of reporting the allocator as native-only
- migrate the generic runtime and Rust client to SDK 0.16's scoped wire codec 2;
product guests must be rebuilt rather than sending codec-1 frames
- migrate the generic runtime and Rust client to SDK 0.16's scoped wire codec 3;
the handshake requires an exact codec match, so product guests built against
an earlier codec must be rebuilt

### Added

- Add shared native and browser Chat main-purse payment authority, explicit
payment review and durable receipt state; keep Chat cryptography inside the
Host rather than product or platform adapters (#709).

- Add `account.deviceChat` for host-private Chat v2 identity binding and
identity-route sealing/opening through local or paired account authorities,
guarded by a dedicated, product-scoped Chat-authority permission.
- report local-wallet registration stages and retryable chain-read errors through
a request-scoped browser callback without resubmitting accepted claims
- expose local signing-wallet username registration and chain-verified identity
Expand All @@ -31,6 +39,15 @@ generated from [Conventional Commits](https://www.conventionalcommits.org/).

### Fixed

- persist typed Statement Store allowance approvals and denials per product and
account selector for implicit, idempotent provisioning; explicit requests for
additional quota retain per-operation confirmation and increase semantics.
Stop unscoped product background renewal, including previously recorded
targets, so artifact-scoped revocation cannot be bypassed.
- require separate Chat-authority consent on the local product API as well as
SSO; existing username-disclosure grants do not authorize Chat operations,
and denial or revocation blocks subsequent binding, sealing, and opening (#709)
- move the secret-bearing SSO pairing result instead of cloning it (#709)
- keep host-backed allowance helpers available on Wasm with browser-compatible
polling clocks, while excluding the native-only renewal driver (#540)
- report the immutable PolkaVM runtime revision actually pinned by the optional
Expand Down
Loading
Loading