2026-10-03 · Creator Publishing Hub Personal Social Desk, Audience Profile Scanner, Engagement Watcher, Owned-device Agent Data API, Image Intake
The owned-device data API uses the correct local identity-service request format so verified owner devices can connect.
What changed
- Correct the local device-ownership lookup request format, which previously caused valid owned-device connections to be rejected. Authentication continues to use the actual connecting device and verified owner account.
- The profile evidence, follow history, image processing and revision-checked write workflows from 2026.10.3.04 remain part of this maintained package. Follower cleanup writes retain their separate disabled-by-default gate.
Verification
- The real local identity endpoint identified the verified owned device with matching user, device and network address.
- Twenty-nine focused authentication and API checks passed, including the identity service request-host rejection regression, spoofed claims, foreign/tagged identities, socket failures and write preconditions.
- The complete local application suite passed 781 tests with one platform skip; all 782 passed during Linux deployment. The feature contract and live rendering passed for all nine views. Independent owned-device reads, a durable relationship note write and exact receipt replay succeeded.
- A real private photo upload completed the configured pixel backend and passed fidelity checks as WebP. The original bytes, dimensions and alpha were independently verified; cloud transfer is pending and proprietary watermark-detector verification is unavailable.
Rollout
Installed in the maintained author deployment. Independent owned-device reads, revision-checked writes, durable receipt replay and local image-processing readback are verified. The parallel scanner transition, browser extension activation and native notification producer remain pending as documented in 2026.10.3.04.
Updating
- Install the maintained Social Desk patch and retain the existing private owned-device listener configuration.
- Refresh the PWA after rollout. Browser extension activation remains separate; this connection patch does not send a greeting or remove a follower.
Scope and limitations
- Device ownership must be attested by the local identity service; a caller label, forwarded identity header or shared-network membership alone is insufficient.
- Scanner coverage remains partial; the packaged parallel-worker update still requires the coordinator plan, an idle transition and a real canary.
- The native new-follow notification capture producer remains pending. Pixel-cleanup backend completion remains distinct from proprietary watermark-detector verification.