feat(platform,auth): add secure Adjust onboarding - #26
Conversation
WHY: connect Adjust independently with per-app attribution mappings without exposing credentials or trusting unsigned user cookies. WHAT: add encrypted token setup, app/event discovery, normalized latest-window reports, additive snapshot storage and isolated provider E2E coverage. Live account configuration and automatic sync remain opt-in.
HEAD-specific release reviewReviewed No unresolved blocking findings remain. Transport, pure normalization, Review findings resolved before this HEAD: generic disconnect filter bypass, Verified on this HEAD:
Release scope is the configuration page, additive snapshot table and dedicated |
Release status: merged and built, deployment blocked
Production deployment has NOT run. Neither the encryption secret nor its IAM Resume after authorization: create Do not connect Adjust, import acquisition credentials, enable automatic sync or |
Intent
Provide an independent, secure Adjust setup page so the user can later connect
Luddi and Cuddler, select each app's events and review attributed data. Do not
reuse acquisition configuration or activate a real account during this release.
Changes
mapping with explicit semantic confirmation.
and media IDs. Keep provider app totals separate from dimensional unique users.
user-ID-cookie compatibility path before exposing credential management.
a loopback Adjust fixture. Automatic sync remains off by default.
Broader dashboard metrics, Seedance model/ownership changes and Worker execution
are intentionally not included. The original dirty worktrees are preserved.
Verification
npm test: 470 passed / 38 files.warnings outside changed files;
git diff --checkpassed.f5a30e10de9180712369e23e13512fa720076a4d:CI passed, including
Docker build/runtime smoke; database E2E
passed 59/59 with zero skips, including the migration and all nine Adjust DB
cases. Final desktop/mobile artifacts were inspected.
before correction. No live Adjust, Ark or Seedance requests were made.
Release and Recovery
Deploy only after CI and a HEAD-specific code review pass. Provision a stable
32-byte encryption key in Secret Manager and bind it as
PLATFORM_CREDENTIAL_KEY; never deploy the fixture key or test API override.The user will enter the business token later; no account or schedule is enabled.
The migration only adds a table. Before any real Adjust credential is stored,
rollback can restore the previous Cloud Run revision while retaining the empty
table and key. After encrypted credentials are stored, older Adjust clients
cannot consume them: prefer a forward fix and do not blindly roll back to the
legacy plaintext client. Never rotate/delete the encryption key during rollback.
True account permissions/metric definitions remain to be reconciled by the user.
This release does not implement media-cost joins, daily history or CPA/CPP/ROAS.
See
docs/agent/adjust-setup-validation.mdfor the reproducible checks and limits.