Skip to content

[DEV-1719] Document protected settings and server API integrations - #299

Draft
tonytlwu wants to merge 2 commits into
masterfrom
feature/DEV-1719-server-integrations
Draft

tonytlwu wants to merge 2 commits into
masterfrom
feature/DEV-1719-server-integrations

Conversation

@tonytlwu

@tonytlwu tonytlwu commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Updates the canonical App Actions V3, V3 App Settings Convention and Fliplet.App references to match the implementation. Covers visibility and trusted authors, explicit credential writes/status/deletion, server-only reads, rotation, HTTPS origins/limits, execution envelopes, safe logs and a complete integration example.

Regenerates the existing AI discovery indexes and capability catalog so Studio and other doc consumers can discover the same guidance. Documents compatibility for older Studio credential writes and the fixed execution-error messages. No extra documentation surface is introduced. Publish with the corresponding runtime; local doc edits alone do not change what deployed Studio fetches.

Jira: DEV-1719

Delivery and remaining verification

This is part of the agreed Studio V3 integration scope: private/protected settings in server actions, credential management, server HTTP calls, AI guidance and developer documentation. Deploy the compatible browser service before the API, then Studio; publish developer docs with the matching runtime. No tunnel, capabilities endpoint, enable flag or mandatory Lambda version pinning is included. No deployment or production credential migration has been performed.

The existing payload-to-HTML issue is separately tracked in DEV-2022; it is outside this change and is not a release prerequisite. Full authenticated builder scenarios remain unverified. Keep this PR in draft until the receiving developer has reviewed the implementation and remaining QA.

Test plan

Verification

  • Strict docs frontmatter/link/index build passed: cd docs && npm run check:docs.
  • All 163 docs unit tests passed: npm run test:unit.
  • Jekyll and Markdown sibling builds passed: bundle exec jekyll build && node bin/copy-md-siblings.mjs. Existing Liquid warnings remain in unrelated pages.
  • Source/reader reviews completed. Offline example checks passed for settings lifecycle, six provider outcomes and three caller outcomes. Provider calls were mocked; no live-provider success is claimed.
  • Rendered desktop and narrow layouts inspected; retained anchors and source Markdown siblings verified.
  • npm run check:v3-catalog reports an existing fliplet-service-worker entry absent from live assets. Catalog package names are unchanged from the base; this unrelated check is not passing.

QA acceptance

  1. Build the docs and open API/core/app-actions-v3.html#server-api-integrations, API/v3/app-settings.html and API/core/app.html#settings. Check tables/code blocks, internal links and preserved anchors.
  2. On a compatible staging runtime, follow the credential setup/action creation/run example with a controlled provider. Verify missing credentials, 401, malformed/unsuccessful JSON, transport rejection and successful documented JSON do not get confused with execution-envelope success.
  3. Fetch the generated Markdown and V3 catalog; confirm the settings and integration guidance is present and action lookup leads to the V3 reference. Confirm any/client do not receive private/protected settings through Fliplet.App.Settings; permissions on separate REST endpoints are unchanged.

Related PRs and documentation


Actions declared `client` or `any` do not receive private or protected settings, including when an `any` action is invoked on the server. Opening an action's compiled HTML in a browser does not provide protected values. See [App Actions V3](../core/app-actions-v3.md) for execution and integration requests.

Protected values are omitted from ordinary app responses and app-version snapshots. Restoring an app version preserves its current protected settings rather than restoring old credentials. Cloning an app does not provision credentials for the clone; configure them separately.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This says cloning does not provision credentials, but the linked API clone path only removes protected __… and legacy _aiartifact_… settings. Ordinary editor-private keys are copied, including the _saml2 certificate example recommended later on this page. This could lead editors to assume those credentials were omitted. Could we clarify that only protected credentials are excluded and that _… settings are cloned?

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Deploying fliplet-cli with  Cloudflare Pages  Cloudflare Pages

Latest commit: e750b07
Status: ✅  Deploy successful!
Preview URL: https://66e5e1c8.fliplet-cli.pages.dev
Branch Preview URL: https://feature-dev-1719-server-inte.fliplet-cli.pages.dev

View logs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants