On this page
  1. Durable handoff
  2. Live recipient checks
  3. Data-only transport and recovery
  4. Qualification boundary

Data-only background sync hints

Compose Devices and durable Delivery without a notification inbox while keeping content and recipient authority in the application.

A sync hint means “ask the authenticated sync API for changes,” not “apply this document.” Compose Devices with the durable delivery worker, without requiring a notification inbox. Enrollment, scheduling, coalescing, and the sync protocol remain application-owned.

Durable handoff

In the product transaction, select eligible recipients and exclude the origin device. Reserve a host-owned coalescing batch with a unique tenant/recipient/target/revision key. Closing the batch freezes its content and recipient scope. Persist the protected immutable reference, register the native attempt, and append queue outbox intent on the same physical transaction.

Use only a hint such as { kind: 'sync-required', version: '1' }: no document text, names, paths, access tokens, or previews. Reuse the closed batch/target identity on enqueue retry and redelivery. A genuinely new batch gets a new revision; an uncertain send must not receive a new key to bypass quarantine. Set finite attempts and a freshness deadline. Collapse IDs and provider TTLs are optimizations, not durable identity.

Live recipient checks

The worker's transactional prepare resolves immutable intent, recomputes its request hash, and checks current membership, enrollment, preferences, suppression, expiry, and origin-device exclusion. Unavailable authority throws; confirmed denial returns a denied decision.

Wrap Devices' encrypted target resolver with a product PushTargetSource. createDevicesPushTargetSource alone resolves the user/app/token; it does not authorize product enrollment or exclude the origin. Recheck in resolve immediately before provider I/O, return null for revoked/expired/origin targets, and delegate permanent feedback to devices.recordPushFeedback. Bind provider slot/app identity to the intent. Never log decrypted credentials.

The worker commits submission before dispatch and uses snapshotted portable data. Keep SDK clients and credentials in configured closures, not queue payloads. Revocation after the final check cannot recall an accepted push; the sync API independently authorizes every content read.

Data-only transport and recovery

APNs requires aps: { 'content-available': 1 } plus background headers and the correct topic on the injected client. Expo uses data and contentAvailable with a compatible SDK. FCM uses data, with the appropriate APNs background configuration for Apple devices. Omit alert/title/body/notification fields. Web Push can transport data, but browser policies may require a visible notification; this does not promise silent browser sync or headless execution on any OS.

Permanent destination rejection invalidates only the selected token. Malformed receipts and lost responses are non-retryable uncertainty, not grounds to invalidate a valid token. The worker conservatively quarantines thrown dispatch errors; verified refusal evidence can permit a host reconciler to use native reconcile/retry within the original budget and deadline. Ordinary queue retry grants no new send. Failed outcome persistence requires receipt repair, not resubmission.

Provider acceptance is not device execution. Review SDK retries/deadlines separately; one adapter invocation is not proof of one network submission. Foreground authenticated sync remains the recovery path for lost hints.

Qualification boundary

Native provider/slot unit fixtures cover recipient rechecks, permanent rejection, malformed outcomes, and concurrent/replayed work without resending accepted/unknown attempts. They do not qualify real devices, SDK network retries, a durable host coalescer, or your application's physical transaction. Exercise those boundaries before enabling a production worker.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software