Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,10 @@ OpenSSF Best Practices self-certification notes: [`docs/openssf-best-practices.m
`CHANGELOG.md`.
- Homepage footer and README community tables now link Support, Security, and Contributing for
feedback and contribution discovery.
- Project status copy no longer claims zero production evidence. It states pre-1.0 API instability,
live first-party L4 on `https://xid.dev`, and that external IdP/SaaS/social/SMS paths stay
non-production-supported until their L4 rows exist (`README*`, `SECURITY.md`, `SUPPORT.md`, site
home evidence blurb).

### Added

Expand Down
25 changes: 16 additions & 9 deletions README.de.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,15 +13,22 @@ vom Apex, während ein isolierter Console Worker die Verwaltungsoberfläche bere

## Projektstatus

**Vor 1.0. Noch nicht produktiv einsetzen.** Jede unten genannte Fähigkeit ist ausschließlich durch
lokale Nachweise belegt: Unit-Tests, Integrationstests in der Workers-Runtime sowie Browser- bzw.
Protokoll-Client-Smoke-Tests gegen einen lokalen Build. Nichts wurde Ende-zu-Ende gegen einen echten
externen Identity Provider, eine echte nachgelagerte SaaS-Anwendung, einen echten
Social-OAuth-Provider oder echten SMS-/WhatsApp-Versand verifiziert. Evidenzstufen (L0 bis L4) und
die Unterstützungsgrade je Funktion sind in
[`docs/protocols/README.md`](docs/protocols/README.md) definiert; dieses Dokument ist gegenüber
jeder Zusammenfassung hier maßgeblich. Schnittstellen, Datenbankschema und Paket-APIs können sich
ohne Deprecation-Phase ändern.
**Vor 1.0 (Pre-1.0).** Bis 1.0.0 können öffentliche APIs, Datenbankschema und Paket-Oberflächen noch
ohne lange Deprecation-Phase ändern.

Die gehostete Bereitstellung [https://xid.dev](https://xid.dev) läuft produktiv. First-Party-Pfade
von Hosted Auth, Console, Management API und verwandten Kernflächen haben **Production-(L4)**-Nachweise
gegen diese Instanz (siehe [`docs/api-contracts.md`](docs/api-contracts.md) und
`pnpm run smoke:production*`). Die breitere Matrix stützt sich weiterhin auf lokale L0–L3-Unit-,
Workers-Runtime- und Browser- bzw. Protokoll-Client-Tests.

**Nicht** production-supported, solange keine echte L4-Zeile für den Pfad vorliegt: Enterprise-IdPs
(Okta, Microsoft Entra ID u. a.), Downstream-SaaS-SSO/SCIM (Slack, GitHub Enterprise u. a.), Social
OAuth mit echten Secrets und Callbacks sowie SMS-/WhatsApp-Zustellung. Lokale Implementierung oder
`provider-ready` ist keine production-supported-Aussage.

Evidenzstufen (L0 bis L4) und Unterstützungsgrade je Funktion stehen in
[`docs/protocols/README.md`](docs/protocols/README.md) und haben Vorrang vor jeder Zusammenfassung hier.

## Warum XID

Expand Down
25 changes: 16 additions & 9 deletions README.es.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,15 +13,22 @@ desde apex, mientras que un Console Worker aislado sirve la interfaz de gestión

## Estado del proyecto

**Pre-1.0. Todavía no lo pongas en producción.** Cada capacidad descrita más abajo se apoya
únicamente en evidencia local: tests unitarios, tests de integración sobre el runtime de Workers y
pruebas de humo con navegador o con clientes de protocolo contra una build local. Nada se ha
verificado de extremo a extremo contra un proveedor de identidad externo real, una aplicación SaaS
downstream real, un proveedor OAuth social real ni una entrega real por SMS/WhatsApp. Los niveles de
evidencia (L0 a L4) y los niveles de soporte por funcionalidad están definidos en
[`docs/protocols/README.md`](docs/protocols/README.md), que prevalece sobre cualquier resumen de
esta página. Las interfaces, el esquema de base de datos y las APIs de los paquetes pueden cambiar
sin periodo de deprecación.
**Pre-1.0.** Hasta la 1.0.0, las API públicas, el esquema de base de datos y las superficies de
paquetes pueden seguir cambiando sin un periodo largo de deprecación.

El despliegue alojado [https://xid.dev](https://xid.dev) está en vivo. Las rutas first-party de
Hosted Auth, Console, Management API y núcleos relacionados tienen evidencia **production (L4)**
contra ese despliegue (ver [`docs/api-contracts.md`](docs/api-contracts.md) y las gates
`pnpm run smoke:production*`). El resto de la matriz sigue apoyándose en pruebas locales L0–L3
(unitarias, runtime de Workers, navegador o cliente de protocolo).

**No** es production-supported mientras no exista una fila L4 real para esa ruta: IdP empresariales
(Okta, Microsoft Entra ID, etc.), SSO/SCIM SaaS downstream (Slack, GitHub Enterprise, etc.), OAuth
social con secretos y callbacks reales, y entrega SMS/WhatsApp. La implementación local o el estado
`provider-ready` no es una afirmación production-supported.

Los niveles de evidencia (L0 a L4) y de soporte por funcionalidad están en
[`docs/protocols/README.md`](docs/protocols/README.md), que prevalece sobre cualquier resumen aquí.

## Por qué XID

Expand Down
25 changes: 16 additions & 9 deletions README.fr.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,15 +14,22 @@ de gestion.

## État du projet

**Pré-1.0. Ne déployez pas encore ce projet en production.** Chacune des capacités décrites
ci-dessous ne repose que sur des preuves locales : tests unitaires, tests d'intégration sur le
runtime Workers et tests de fumée menés depuis un navigateur ou un client de protocole contre un
build local. Rien n'a été vérifié de bout en bout face à un véritable fournisseur d'identité
externe, à une véritable application SaaS en aval, à un véritable fournisseur OAuth social ou à une
véritable livraison SMS/WhatsApp. Les niveaux de preuve (L0 à L4) et les niveaux de support par
fonctionnalité sont définis dans [`docs/protocols/README.md`](docs/protocols/README.md), qui fait
autorité sur tout résumé présenté ici. Les interfaces, le schéma de base de données et les API des
packages peuvent changer sans période de dépréciation.
**Pré-1.0.** Jusqu'à la 1.0.0, les API publiques, le schéma de base de données et les surfaces de
packages peuvent encore évoluer sans longue période de dépréciation.

Le déploiement hébergé [https://xid.dev](https://xid.dev) est en production. Les chemins first-party
Hosted Auth, Console, Management API et cœurs associés ont des preuves **production (L4)** contre ce
déploiement (voir [`docs/api-contracts.md`](docs/api-contracts.md) et les gates
`pnpm run smoke:production*`). Le reste de la matrice s'appuie encore largement sur les tests locaux
L0–L3 (unitaires, runtime Workers, navigateur ou client de protocole).

**Pas** production-supported tant qu'il n'existe pas de ligne L4 réelle pour le chemin concerné :
IdP d'entreprise (Okta, Microsoft Entra ID, etc.), SSO/SCIM SaaS aval (Slack, GitHub Enterprise,
etc.), OAuth social avec secrets et callbacks réels, livraison SMS/WhatsApp. Une implémentation
locale ou un statut `provider-ready` n'est pas une affirmation production-supported.

Les niveaux de preuve (L0 à L4) et de support par fonctionnalité sont définis dans
[`docs/protocols/README.md`](docs/protocols/README.md), qui prime sur tout résumé ici.

## Pourquoi XID

Expand Down
22 changes: 14 additions & 8 deletions README.ja.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,14 +13,20 @@ Worker は management UI を提供する。

## プロジェクトの状態

**1.0 未満。まだ production で動かしてはならない。** 以下に挙げる機能はすべてローカルの証跡のみに
裏付けられている。すなわち unit test、Workers runtime 上の integration test、そしてローカルビルドに
対する browser または protocol client の smoke test である。実在する外部 identity provider、実在する
下流 SaaS アプリケーション、実在する social OAuth provider、実際の SMS/WhatsApp 配信に対して
end-to-end で検証したものは一つもない。証跡の階層(L0 から L4)と機能ごとのサポートレベルは
[`docs/protocols/README.md`](docs/protocols/README.md) に定義されており、ここに書いた要約よりも
そちらが正となる。インターフェース、データベース schema、package API は非推奨期間を置かずに
変更されうる。
**1.0 未満 (Pre-1.0)。** 1.0.0 までは公開 API、データベース schema、package 表面は長い非推奨期間なしで
変わりうる。

ホスト済みデプロイ [https://xid.dev](https://xid.dev) は稼働中である。第一者の Hosted Auth、Console、
Management API および関連コア経路は、そのデプロイに対する **production (L4)** 証跡がある
([`docs/api-contracts.md`](docs/api-contracts.md) と `pnpm run smoke:production*` を参照)。より広い
行列は引き続きローカル L0–L3 の unit / Workers runtime / browser または protocol client テストに依る。

対応する実 L4 行が無い限り **production-supported ではない**: 企業 IdP (Okta、Microsoft Entra ID など)、
下流 SaaS SSO/SCIM (Slack、GitHub Enterprise など)、実シークレットと callback を伴う social OAuth、
SMS/WhatsApp 配信。ローカル実装や `provider-ready` は production-supported の主張ではない。

証跡階層 (L0 から L4) と機能ごとのサポートレベルは
[`docs/protocols/README.md`](docs/protocols/README.md) が正であり、ここでの要約より優先する。

## なぜ XID か

Expand Down
22 changes: 14 additions & 8 deletions README.ko.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,14 +13,20 @@ Core Worker는 OIDC/OAuth, 멀티 테넌트 RBAC, 엔터프라이즈 SSO 페더

## 프로젝트 상태

**Pre-1.0 단계입니다. 아직 프로덕션에서 사용하지 마십시오.** 아래의 모든 기능은 로컬 근거만
확보한 상태입니다. 즉 유닛 테스트, Workers 런타임 통합 테스트, 그리고 로컬 빌드를 대상으로 한
브라우저 또는 프로토콜 클라이언트 스모크 테스트뿐입니다. 실제 외부 Identity Provider, 실제 하위
SaaS 애플리케이션, 실제 소셜 OAuth provider, 실제 SMS/WhatsApp 발송에 대해 종단 간으로 검증된
항목은 없습니다. 근거 등급(L0에서 L4까지)과 기능별 지원 수준은
[`docs/protocols/README.md`](docs/protocols/README.md)에 정의되어 있으며, 이 문서의 요약보다 해당
문서가 우선합니다. 인터페이스, 데이터베이스 스키마, 패키지 API는 deprecation 기간 없이 변경될 수
있습니다.
**Pre-1.0.** 1.0.0 이전에는 공개 API, 데이터베이스 스키마, 패키지 표면이 긴 deprecation 기간 없이
바뀔 수 있습니다.

호스팅 배포 [https://xid.dev](https://xid.dev)는 운영 중입니다. 1차 Hosted Auth, Console, Management
API 및 관련 핵심 경로는 해당 배포에 대한 **production (L4)** 근거가 있습니다
([`docs/api-contracts.md`](docs/api-contracts.md), `pnpm run smoke:production*` 참조). 더 넓은 매트릭스는
여전히 로컬 L0–L3 유닛/Workers 런타임/브라우저 또는 프로토콜 클라이언트 테스트에 의존합니다.

대응 실제 L4 행이 있기 전까지 **production-supported가 아닌** 항목: 엔터프라이즈 IdP(Okta, Microsoft
Entra ID 등), 다운스트림 SaaS SSO/SCIM(Slack, GitHub Enterprise 등), 실제 시크릿·콜백이 있는 소셜
OAuth, SMS/WhatsApp 발송. 로컬 구현 또는 `provider-ready`는 production-supported 주장이 아닙니다.

근거 등급(L0–L4)과 기능별 지원 수준은
[`docs/protocols/README.md`](docs/protocols/README.md)가 권위 문서이며 이 요약보다 우선합니다.

## XID를 만든 이유

Expand Down
23 changes: 16 additions & 7 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,13 +13,22 @@ isolated Console Worker serves the management UI.

## Project status

**Pre-1.0. Do not run this in production yet.** Every capability below is backed by local evidence
only: unit tests, Workers-runtime integration tests, and browser or protocol-client smoke tests
against a local build. Nothing has been verified end-to-end against a real external identity
provider, a real downstream SaaS application, a real social OAuth provider, or real SMS/WhatsApp
delivery. Evidence tiers (L0 to L4) and per-feature support levels are defined in
[`docs/protocols/README.md`](docs/protocols/README.md), which is authoritative over any summary
here. Interfaces, database schema, and package APIs may change without a deprecation period.
**Pre-1.0.** Until 1.0.0, public APIs, database schema, and package surfaces may still change without
a long deprecation window.

The hosted deployment at [https://xid.dev](https://xid.dev) is live. First-party Hosted Auth,
Console, Management API, and related core paths have **production (L4)** evidence against that
deployment (see [`docs/api-contracts.md`](docs/api-contracts.md) and the `pnpm run smoke:production*`
gates). Broader coverage still rests on local L0–L3 unit, Workers-runtime, and browser or protocol
client tests.

**Not** production-supported until a real L4 row exists for that path: enterprise IdPs (Okta,
Microsoft Entra ID, and peers), downstream SaaS SSO/SCIM (Slack, GitHub Enterprise, and peers),
social OAuth with real provider secrets and callbacks, and SMS/WhatsApp delivery. Local
implementation or `provider-ready` is not a production-supported claim.

Evidence tiers (L0 to L4) and per-feature support levels live in
[`docs/protocols/README.md`](docs/protocols/README.md), which is authoritative over any summary here.

## Why XID

Expand Down
24 changes: 16 additions & 8 deletions README.pt-BR.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,14 +13,22 @@ diretamente no apex, enquanto um Console Worker isolado fornece a interface de g

## Situação do projeto

**Pré-1.0. Ainda não coloque isto em produção.** Todos os recursos abaixo têm como respaldo apenas
evidências locais: testes unitários, testes de integração no runtime dos Workers e smoke tests via
navegador ou cliente de protocolo contra um build local. Nada foi verificado de ponta a ponta contra
um provedor de identidade externo real, uma aplicação SaaS downstream real, um provedor OAuth social
real ou entrega real de SMS/WhatsApp. Os níveis de evidência (L0 a L4) e o grau de suporte por
recurso estão definidos em [`docs/protocols/README.md`](docs/protocols/README.md), que prevalece
sobre qualquer resumo apresentado aqui. Interfaces, schema de banco de dados e APIs dos pacotes podem
mudar sem período de depreciação.
**Pré-1.0.** Até a 1.0.0, APIs públicas, schema de banco e superfícies de pacotes ainda podem mudar
sem um longo período de depreciação.

O deploy hospedado [https://xid.dev](https://xid.dev) está no ar. Caminhos first-party de Hosted
Auth, Console, Management API e núcleos relacionados têm evidência **production (L4)** contra esse
deploy (ver [`docs/api-contracts.md`](docs/api-contracts.md) e as gates
`pnpm run smoke:production*`). O restante da matriz ainda se apoia em testes locais L0–L3 (unitários,
runtime Workers, navegador ou cliente de protocolo).

**Não** é production-supported enquanto não existir linha L4 real para o caminho: IdPs empresariais
(Okta, Microsoft Entra ID etc.), SSO/SCIM SaaS downstream (Slack, GitHub Enterprise etc.), OAuth
social com segredos e callbacks reais, e entrega SMS/WhatsApp. Implementação local ou
`provider-ready` não é afirmação production-supported.

Níveis de evidência (L0 a L4) e de suporte por recurso estão em
[`docs/protocols/README.md`](docs/protocols/README.md), que prevalece sobre qualquer resumo aqui.

## Por que o XID

Expand Down
18 changes: 13 additions & 5 deletions README.zh-Hans.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,19 @@ OIDC/OAuth、多租户 RBAC、企业 SSO 联邦、Hosted Auth 与 account 页面

## 项目状态

**Pre-1.0,请勿用于生产环境。** 下文列出的每一项能力目前都只有本地证据支撑:单元测试、Workers 运行时
集成测试,以及针对本地构建的浏览器或协议客户端冒烟测试。没有任何一项针对真实外部身份提供方、真实下游
SaaS 应用、真实社交 OAuth 提供方或真实 SMS/WhatsApp 投递做过端到端验证。证据分级(L0 到 L4)与各功能的
支持级别定义在 [`docs/protocols/README.md`](docs/protocols/README.md),该文档的效力高于这里的任何概述。
接口、数据库 schema 与包 API 可能在没有弃用期的情况下变更。
**Pre-1.0。** 在 1.0.0 之前,公开 API、数据库 schema 与包表面仍可能在没有长弃用期的情况下变更。

托管部署 [https://xid.dev](https://xid.dev) 已在线。第一方 Hosted Auth、Console、Management API 及
相关核心路径对该部署已有 **production (L4)** 证据(见 [`docs/api-contracts.md`](docs/api-contracts.md)
与 `pnpm run smoke:production*` 门禁)。更广的协议矩阵仍主要依赖本地 L0–L3 单元测试、Workers 运行时
集成测试,以及浏览器或协议客户端冒烟测试。

在出现对应真实 L4 记录之前,**尚不能**称为 production-supported 的包括:企业 IdP(Okta、Microsoft
Entra ID 等)、下游 SaaS SSO/SCIM(Slack、GitHub Enterprise 等)、带真实密钥与回调的社交 OAuth,以及
SMS/WhatsApp 投递。本地实现或 `provider-ready` 不等于 production-supported。

证据分级(L0 到 L4)与各功能支持级别以
[`docs/protocols/README.md`](docs/protocols/README.md) 为准,效力高于此处任何概述。

## 为什么是 XID

Expand Down
12 changes: 7 additions & 5 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,13 @@ tenant deployed on it. Security reports are handled with priority over feature w

## Maturity statement

**XID is pre-1.0 and is not production-supported.** End-to-end verification against real external
systems (enterprise IdPs such as Okta, Microsoft Entra ID, and Google Workspace; downstream SaaS
SCIM targets; social login providers; SMS and WhatsApp delivery) is incomplete for every capability.
Local implementation with unit and integration tests does not imply production readiness. Deploying
XID to handle real user credentials today is at your own risk.
**XID is pre-1.0.** Public APIs and schema may still change before 1.0.0. The hosted deployment at
https://xid.dev is live, and first-party Hosted Auth, Console, and Management API paths have
production (L4) evidence against that instance. Capabilities that depend on **external** systems
(enterprise IdPs such as Okta, Microsoft Entra ID, and Google Workspace; downstream SaaS SSO/SCIM;
social login providers; SMS and WhatsApp delivery) are **not** production-supported until a real L4
row is recorded for that path. Local L0–L3 evidence is not a production-supported claim. Self-hosting
for real credentials where those external L4 rows are missing remains at your own risk.

This statement is not a reason to withhold a report. It is context for how findings are triaged.

Expand Down
8 changes: 5 additions & 3 deletions SUPPORT.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,9 +39,11 @@ Then:

## Support expectations

Nothing in this repository is production-supported. Verification against real external identity
providers and downstream systems is incomplete. Support levels follow the L0-L4 evidence tiers
defined in `docs/protocols/` and `docs/sdks/platform-matrix.md`; those documents are authoritative.
Community support is best-effort with no service level agreement. First-party paths on the hosted
deployment may have production (L4) evidence; external IdP, SaaS SSO/SCIM, social OAuth, and
SMS/WhatsApp claims stay non-production-supported until the matching L4 row exists. Support levels
follow the L0–L4 evidence tiers in `docs/protocols/` and `docs/sdks/platform-matrix.md`; those
documents are authoritative.

Commercial support for the hosted service at [xid.dev](https://xid.dev) is separate from this
repository and is not covered by community channels.
Loading
Loading