Skip to content

Implement server-side identity foundation and Lockr capture - #1260

Draft
jevansnyc wants to merge 3 commits into
mainfrom
spec/lockr-identity-capture
Draft

jevansnyc wants to merge 3 commits into
mainfrom
spec/lockr-identity-capture

Conversation

@jevansnyc

@jevansnyc jevansnyc commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Implements the server-side identity foundation and ID5-only Lockr proxy-response capture, with the reviewed specs and implementation plan.

  • Keep schema-v1 KV records under the full EC ID; add optional expiry/writer/revision and expiry-aware auction/identify reads.
  • Validate explicit source ownership across deploy/config-push/runtime/startup. Owned sources retain read-only identify but reject batch writes and legacy pull.
  • Persist registered /auction body EIDs conservatively during existing finalization. Retire ts-eids ingestion/writer and EID diagnostic emission; preserve inbound strips and authenticated local admin retirement on all adapters.
  • Inspect selected proxy responses within independent 64 KiB wire/decoded limits, preserving original response parts/bytes/stream errors. Stage sealed, consent-restrictive effects and apply after Fastly send, before legacy pull.
  • Add Lockr ID5 parsing, expiry/association validation, redacted logging and independently gated global revoke handling. Preserve ts-ec; no replacement EID cookie.

Verification

  • cargo test-fastly: 219 adapter + 2,924 core tests passed (six core ignored), shared/doc tests passed.
  • cargo test-fastly-reuse, all three native adapter suites, ./scripts/test-cli.sh including required ignored browser fixtures, and native build-digest tests passed.
  • Full JS suite: 1,186 tests across 48 files, no type errors; all 13 JS modules build.
  • Target-matched Clippy passed for all adapters, CLI/codegen and native build-digest tests. Fastly/Axum/Cloudflare development builds passed.
  • Rust formatting, scoped JS/docs formatting and whitespace checks passed. Recording executor tests prove send-before-storage, no-effects/unavailable-storage behavior, and persisted context snapshot handoff.

Evidence and reproducible commands: docs/superpowers/plans/2026-10-09-server-side-identity-foundation-and-lockr.md.

Activation gates / deliberately deferred

This is a draft implementation, not permission to activate capture. The rollout example explicitly sets capture_identity = false and capture_global_withdrawal = false. Capture defaults to true for compatible configuration; operators must explicitly disable it until the gates pass.

Not verified: provider-approved sanitized fixtures/mappings, consent/revoke scope and application-success semantics, overlap ordering, live acceptance, metadata-compatible deployment propagation and old-invocation drain, external diagnostic consumers, and remote CI. Old writers can erase lifecycle metadata and old readers ignore expiry; do not activate managed writes during mixed-binary deployment.

Native LiveRamp resolution, identifier intake, refresh/invalidation scheduling, durable retries and cross-browser linkage remain deferred. Other adapters do not claim Fastly-style post-send KV persistence.

Refs #1246, #1245.

Lockr-issued IDs reach client-side bidders through ortb2.user.ext.eids but
never the server-side auction, the ts-eids cookie, or the EC identity graph
(#1246). This spec captures the IDs in the first-party proxy response from
lockr's API, sets a server-owned HttpOnly cookie on that response, and defers
the KV upsert to the post-send slot so no KV write sits on the hot path.
@ChristianPavilonis ChristianPavilonis changed the title Add proxy-side identity capture design spec for lockr-issued IDs Implement server-side identity foundation and Lockr capture Oct 9, 2026
Comment thread crates/trusted-server-core/src/publisher.rs Dismissed

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants