Invio v1.0.0.1.49.1
·
9 commits
to main
since this release
Invio v1.0.0.1.49.1 — Persistent Browser OAuth + MSI Launch Integration
Official Parent Baseline: Invio v1.0.0.1.49.
Browser OAuth
- Optional
browser_authinterface v1 for trusted executable P13 provider bundles. - System/default browser authorization; no embedded WebView dependency.
- Cryptographically random state, PKCE S256 when declared, strict redirect/state/callback validation, timeout and cancellation.
- Loopback callbacks for provider-supported desktop flows and validated one-time manual callback completion for providers that require production HTTPS redirect infrastructure.
- Provider organization/tenant/company/location discovery may populate a manifest-declared account credential.
- Browser auth never persists access tokens. Refresh/bootstrap credentials flow into the existing protected account credential store only when the user saves the account.
- Existing manual credentials and External Provider Adapter v1 task behavior remain compatible.
Persistent connection
After initial authorization and account save, provider adapters use the stored refresh token to obtain access tokens without repeated user login. Providers that rotate refresh tokens must save and use the latest token through protected OS storage. Reauthorization remains necessary only when the provider grant is revoked/expired, scopes change, or token persistence fails.
MSI
- Existing per-user
%LOCALAPPDATA%\Vib Tools\Invioinstallation and UpgradeCode preserved. - Adds
Start Menu > Vib Tools > Inviopointing at installedInvio.exe. - CI verifies shortcut target and shortcut removal after uninstall.
- Signing Option C: no Authenticode certificate/service is added;
Unknown Publishermay remain.
CI correction
- Clean GitHub Actions checkouts intentionally do not contain the Git-ignored
/project/forensic workspace. - The v1.49.1 repository truthfulness contract now validates tracked release evidence unconditionally and checks private baseline/root-cause records only when a full private
/project/workspace is present. - No runtime, OAuth, MSI, provider, UI, storage, task, or business behavior changes are part of this correction.
Frozen boundaries
No Task state machine, WorkerManager, delivery ledger, database schema, invoice/customer/template/report business logic, provider send semantics, or unrelated UI redesign.
Version mapping: application/tag 1.0.0.1.49.1 / v1.0.0.1.49.1, PE 1.0.1.4901, MSI 1.1.4901, wheel 1.0.0.1.49.1.