Skip to content

Invio v1.0.0.1.49.1

Choose a tag to compare

@github-actions github-actions released this 12 Aug 14:32
· 9 commits to main since this release

Invio v1.0.0.1.49.1 — Persistent Browser OAuth + MSI Launch Integration

Official Parent Baseline: Invio v1.0.0.1.49.

Browser OAuth

  • Optional browser_auth interface v1 for trusted executable P13 provider bundles.
  • System/default browser authorization; no embedded WebView dependency.
  • Cryptographically random state, PKCE S256 when declared, strict redirect/state/callback validation, timeout and cancellation.
  • Loopback callbacks for provider-supported desktop flows and validated one-time manual callback completion for providers that require production HTTPS redirect infrastructure.
  • Provider organization/tenant/company/location discovery may populate a manifest-declared account credential.
  • Browser auth never persists access tokens. Refresh/bootstrap credentials flow into the existing protected account credential store only when the user saves the account.
  • Existing manual credentials and External Provider Adapter v1 task behavior remain compatible.

Persistent connection

After initial authorization and account save, provider adapters use the stored refresh token to obtain access tokens without repeated user login. Providers that rotate refresh tokens must save and use the latest token through protected OS storage. Reauthorization remains necessary only when the provider grant is revoked/expired, scopes change, or token persistence fails.

MSI

  • Existing per-user %LOCALAPPDATA%\Vib Tools\Invio installation and UpgradeCode preserved.
  • Adds Start Menu > Vib Tools > Invio pointing at installed Invio.exe.
  • CI verifies shortcut target and shortcut removal after uninstall.
  • Signing Option C: no Authenticode certificate/service is added; Unknown Publisher may remain.

CI correction

  • Clean GitHub Actions checkouts intentionally do not contain the Git-ignored /project/ forensic workspace.
  • The v1.49.1 repository truthfulness contract now validates tracked release evidence unconditionally and checks private baseline/root-cause records only when a full private /project/ workspace is present.
  • No runtime, OAuth, MSI, provider, UI, storage, task, or business behavior changes are part of this correction.

Frozen boundaries

No Task state machine, WorkerManager, delivery ledger, database schema, invoice/customer/template/report business logic, provider send semantics, or unrelated UI redesign.

Version mapping: application/tag 1.0.0.1.49.1 / v1.0.0.1.49.1, PE 1.0.1.4901, MSI 1.1.4901, wheel 1.0.0.1.49.1.