← Back to parent Epic
MAZENG-FT-49 · Consent-based mobile action requests
Why it matters
Users need a safe way to request a time-sensitive action from an authorized mobile participant.
Expected outcome
Authorized participants can respond remotely without exposing credentials, tokens, or unnecessary project data.
In scope
- Server-authorized sender, recipient, project membership, action type, and recipient consent.
- User-controlled device registration and removal.
- Minimal push payloads with durable delivery evidence and a purpose-built encrypted credential protocol if needed.
- Delivery status
IN_BACKLOG- Owner
- RootAtSkic (product lead)
- Solution approval
- PENDING
Acceptance
Acceptance outcomes
- 01
The server authorizes sender, recipient, project membership, action type, and recipient consent.
- 02
Users control device registration and removal.
- 03
Push payloads contain minimum necessary data, report durable delivery or failure evidence, and expose no credentials or access tokens.
- 04
Credential handoff, if approved, uses a purpose-built encrypted protocol rather than generic notification data.
Dependencies and risks
Dependencies
None recorded.
Risks
- Legacy callers can nominate arbitrary recipients without project-role authorization.
- A tracked Firebase service-account file and logged OAuth access tokens are critical credential exposures that must not be preserved.
- Legacy generic notification transport can expose private keys and must not be treated as accepted behavior.
Authoritative Architecture tasks
No authoritative Architecture tasks are linked.