Back to changelog index

0.6.3

Aug 01, 2026 · 8 packages · 11 unique changes · 4 release entries

appsbundlesintegrationslibsmodules

This release affects the integrations, sharedLibs, solutions familyies.

Run contractspec connect adoption resolve --family integrations to see how it impacts your project.

Release summaries

  • authos-module-v0

    Add the experimental AuthOS module and reusable deterministic UI preview surface.

    maintainer

    The AuthOS module adds fake-adapter preview flows and deterministic UI without taking ownership of production auth behavior.

    integrator

    Reuse the AuthOS module UI for preview and planning while keeping provider execution host/integration owned.

  • authos-uplift-w1-to-w5

    AuthOS Uplift Waves 1–4 — 9 atoms, 10 molecules, 10 organisms, and 5 templates added additively. All pre-existing exports preserved. AuthOsTemplate retained as deprecated alias.

    maintainer

    Waves 1–4 of the AuthOS UI uplift land additively on top of the Track 1/2 baseline. Phase 0 expands AuthOsScreen to 12 values, adds AuthRoute + AuthFlowStep types, and locks bundle-adapter template prop signatures via a compile-time contract test. Phase 1 adds 9 new atoms (AuthCodeInput, PasswordStrengthMeter, IdentityChip, DeviceTrustBadge, RiskScoreMeter, EmailDomainBadge, RecoveryCodeChip, PolicySnippet, OrgRoleChip). Phase 2 adds 10 new molecules (PasswordField, EmailField, OtpField, EmailVerificationBanner, MagicLinkRequestPanel, DeviceCard, ConsentSummary, OrgMemberCard, InviteByEmailComposer, SignInProvidersStrip). Phase 3 adds 10 new organisms (SignUpForm, PasskeySetupForm, EmailVerificationFlow, MagicLinkRequestForm, MagicLinkConsumeFlow, ForgotPasswordForm, ResetPasswordForm, AuditLogTable, InvitationsTable, SsoLandingChooser). Phase 4 adds 5 templates (AuthCenteredTemplate, AuthSplitTemplate, AuthFullScreenTemplate, AuthStepperTemplate, AuthDashboardTemplate) with .web/.native pairs; AuthOsTemplate kept as deprecated alias. All exports added to src/ui/index.ts additively. Waves 5 (hooks) and 6–7 (screens refactor / pages / dual-app wiring) deferred.

    integrator

    Import new atoms, molecules, organisms, and templates from @lssm-tech/module.auth-os. All existing imports continue to work unchanged. To migrate away from the deprecated AuthOsTemplate, replace it with AuthCenteredTemplate (same prop surface).

  • g005-google-calendar-oauth-booking

    Add the least-scope Google Calendar OAuth, availability, known-ID booking, recoverable lifecycle, and fenced protected app-notification integration edge.

    integrator

    Hosts can bind G015 booking saga ports to a least-scope Google edge while keeping OAuth material tenant-encrypted, replacement identities exact, and app notifications atomically claimed and deduplicated.

  • managed-companyos-google-calendar-oauth-journey

    Complete the protected Google Workspace Calendar OAuth journey from planning setup through topology configuration.

    customer

    Authorized administrators can begin Google Workspace Calendar setup from CompanyOS and return to calendar topology configuration after consent.

    integrator

    Google OAuth exchange returns its vault-bound opaque connection key so the host can safely continue the user journey without provider identity.

Deprecations

  • - identifier: AuthOsTemplate; replacement: AuthCenteredTemplate; removalVersion: 1.0.0; reason: AuthOsTemplate was a flat-file alias predating the template taxonomy. AuthCenteredTemplate is the canonical centered layout template and accepts the same props.

Migration guide

  • Replace `import { AuthOsTemplate } from '@lssm-tech/module.auth-os'` with `impor

    Required

    Replace `import { AuthOsTemplate } from '@lssm-tech/module.auth-os'` with `import { AuthCenteredTemplate } from '@lssm-tech/module.auth-os'`.

    1. Replace `import { AuthOsTemplate } from '@lssm-tech/module.auth-os'` with `import { AuthCenteredTemplate } from '@lssm-tech/module.auth-os'`.

Upgrade steps

  • Configure the dedicated server-only Calendar OAuth variables

    assisted

    Configure the MANAGED_COMPANYOS_GOOGLE_CALENDAR_* client, secret, and exact redirect URI plus tenant/account/write/busy calendar topology; do not reuse AuthOS identity-provider OAuth variables.

    Packages: @lssm-tech/integration.provider-calendar, @lssm-tech/integration.opa-calendar-bridge, @lssm-tech/integration.opa-notification-bridge, @lssm-tech/lib.organization-planning-runtime

    1. Keep provider credentials in the deployment secret manager.
    2. Configure exactly one owned write calendar and all required busy calendars.
    3. Keep polling and scheduled reconciliation enabled; broad event sync is not approved.
  • Register the exact Google Calendar callback

    manual

    Register the documented API callback URI in the Google OAuth application before enabling user authorization.

    Packages: @lssm-tech/integration.provider-calendar, @lssm-tech/app.api-application-monolith, @lssm-tech/app.web-application-monolith, @lssm-tech/bundle.managed-companyos

    1. Configure the dedicated MANAGED_COMPANYOS_GOOGLE_CALENDAR_* values and register the exact HTTPS callback from the production runbook.
    2. Verify that APP_WEB_BASE_URL is the trusted CompanyOS web origin so the callback can redirect to protected topology setup.
  • Adopt AuthOS module previews safely

    assisted

    Use the module UI as an additive deterministic preview surface with production auth delegated to hosts and integrations.

    Packages: @lssm-tech/module.auth-os

    1. Use fake adapters for local previews.
    2. Keep production provider wiring outside the module preview layer.
  • Switch from AuthOsTemplate to AuthCenteredTemplate

    assisted

    AuthOsTemplate still works but is deprecated. Rename the import to AuthCenteredTemplate and verify prop types — they are compatible.

    Packages: @lssm-tech/module.auth-os

  • Adopt new organisms for auth flows

    manual

    SignUpForm, MagicLinkRequestForm, MagicLinkConsumeFlow, ForgotPasswordForm, ResetPasswordForm, SsoLandingChooser, AuditLogTable, and InvitationsTable replace ad-hoc auth UI in host apps. Each accepts an optional AuthObservability port for analytics.

    Packages: @lssm-tech/module.auth-os

Unique release changes

  • - Add the least-scope Google Calendar OAuth, availability, known-ID booking, recoverable lifecycle, and fenced protected app-notification integration edge.

    4 packages · 4 occurrences

  • - Complete the protected Google Workspace Calendar OAuth journey from planning setup through topology configuration.

    4 packages · 4 occurrences

  • - Configure the MANAGED_COMPANYOS_GOOGLE_CALENDAR_* client, secret, and exact redirect URI plus tenant/account/write/busy calendar topology; do not reuse AuthOS identity-provider OAuth variables.

    4 packages · 4 occurrences

  • - Register the documented API callback URI in the Google OAuth application before enabling user authorization.

    4 packages · 4 occurrences

  • - Add the experimental AuthOS module and reusable deterministic UI preview surface.

    1 packages · 1 occurrences

  • - AuthOS Uplift Waves 1–4 — 9 atoms, 10 molecules, 10 organisms, and 5 templates added additively. All pre-existing exports preserved. AuthOsTemplate retained as deprecated alias.

    1 packages · 1 occurrences

  • - AuthOsTemplate still works but is deprecated. Rename the import to AuthCenteredTemplate and verify prop types — they are compatible.

    1 packages · 1 occurrences

  • - identifier: AuthOsTemplate; replacement: AuthCenteredTemplate; removalVersion: 1.0.0; reason: AuthOsTemplate was a flat-file alias predating the template taxonomy. AuthCenteredTemplate is the canonical centered layout template and accepts the same props.

    1 packages · 1 occurrences

  • - Replace `import { AuthOsTemplate } from '@lssm-tech/module.auth-os'` with `import { AuthCenteredTemplate } from '@lssm-tech/module.auth-os'`.

    1 packages · 1 occurrences

  • - SignUpForm, MagicLinkRequestForm, MagicLinkConsumeFlow, ForgotPasswordForm, ResetPasswordForm, SsoLandingChooser, AuditLogTable, and InvitationsTable replace ad-hoc auth UI in host apps. Each accepts an optional AuthObservability port for analytics.

    1 packages · 1 occurrences

  • - Use the module UI as an additive deterministic preview surface with production auth delegated to hosts and integrations.

    1 packages · 1 occurrences

Impacted packages

  • @lssm-tech/app.api-application-monolith

    Layer: apps · 2 changes

  • @lssm-tech/app.web-application-monolith

    Layer: apps · 2 changes

  • @lssm-tech/bundle.managed-companyos

    Layer: bundles · 2 changes

  • @lssm-tech/integration.opa-calendar-bridge

    Layer: integrations · 2 changes

  • @lssm-tech/integration.opa-notification-bridge

    Layer: integrations · 2 changes

  • @lssm-tech/integration.provider-calendar

    Layer: integrations · 2 changes

  • @lssm-tech/lib.organization-planning-runtime

    Layer: libs · 2 changes

  • @lssm-tech/module.auth-os

    Layer: modules · 5 changes