Skip to content

feat: scoped drafts, event feed and conversion reporting (package 3) - #87

Draft
nikolajIvanov wants to merge 4 commits into
diwenne:mainfrom
nikolajIvanov:feat/upstream-integration-events
Draft

nikolajIvanov wants to merge 4 commits into
diwenne:mainfrom
nikolajIvanov:feat/upstream-integration-events

Conversation

@nikolajIvanov

Copy link
Copy Markdown

Package 3: scoped draft and event integrations (dependent draft)

Prerequisites: read-only API/MCP #84, creator workflow #85 and durable delivery #86.
This branch contains those prerequisite changes, including a cherry-pick of #84. The upstream diff is therefore cumulative, not a claim that all files belong to this package.
The package-only review is this comparison or the single feature commit.
Merge the prerequisites first, then rebase this draft; do not merge the shared changes twice.

Changes

  • Opt-in scopes: drafts:write, events:read, conversions:write. Existing keys retain their scopes and exact expiration dates; new keys default to read-only.
  • REST and MCP create inactive DRAFT campaigns with explicitly provided links, workspace/account checks and atomic, idempotent creation of links, revision and event. Deleted drafts return 409 on replay rather than being resurrected.
  • MCP validation checks configuration only. No activation, publish, send-message or provider-token tools are added.
  • Pull-based settled event feed with bounded pages, source-aware cursors and real tied-timestamp PostgreSQL regressions.
  • Idempotent externally observed conversion reporting and safe workspace-scoped aggregate conversion history. Link clicks do not prove conversions or identify people.
  • Additive IntegrationEvent migration only in this package.

Verification

  • 432 tests / 39 files passed with real PostgreSQL; all 26 migrations applied successfully to a disposable local database.
  • Full TypeScript, targeted ESLint, diff checks and actual production build passed with unchanged upstream dependencies.
  • Real local session-authenticated HTTP/MCP/REST checks passed: concurrent draft/conversion retries, inactive drafts, account/workspace isolation, event feed, aggregate history, old expiry, scopes, Origin boundaries and revocation.
  • Independent reviewer reran the full PostgreSQL suite and both real HTTP scripts; all 24 package-specific files were reviewed, including privacy and prerequisite composition.
  • No production deployment, real keys, real Meta messages or interactive client/Instagram E2E were performed.

Risks and release notes

Apply prerequisite and new migrations before starting web and worker. See docs/integration-writes.md.
The event feed is at-least-once: complete pagination, checkpoint nextSince, replay the 15-minute overlap and dedupe by eventId plus status. Transactions beyond the overlap need a wider replay; this is not an immutable audit of every intermediate status.
Integration events include the caller-supplied opaque conversion reference/value, so grant events:read only to trusted consumers. Delivery projections exclude recipient IDs, raw payloads and errors.
No OAuth/DCR server, automatic CRM push, auth/SMTP, Docker, worker or dependency changes in the package-specific commit. Existing upstream dependency findings are unchanged.
Maintainer CI/preview authorization and eventual merge are separate from this local verification.

@vercel

vercel Bot commented Oct 3, 2026

Copy link
Copy Markdown

@nikolajIvanov is attempting to deploy a commit to the diwenne's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant