Secrets have one owner.
Use only the widget/browser credential class restricted to exact origins. Validate every postMessage/callback payload and keep privileged operations on the server.
A credential-free nearby iframe host with loading, ready, fallback, candidate, committed, and destroyed application states.
The canonical file manifest is also the archive contract. Common evidence, environment, manifest, and acceptance files accompany platform-specific source.
README.mdSetup and first-success boundarySTARTER_MANIFEST.jsonMachine-readable project scope.env.exampleBlank non-secret configurationEVIDENCE.mdSource and selection boundaryACCEPTANCE.mdSuccess and hostile-path proofindex.htmlAccessible widget hosthost.jsExplicit iframe lifecycleHOST_STATES.mdApplication-owned stateUse only the widget/browser credential class restricted to exact origins. Validate every postMessage/callback payload and keep privileged operations on the server.
The current public Web Plugins guide spans current vector and legacy raster integration branches; source activity is not a support promise. Confirm the exact widget, script, origin, event schema, release, entitlement, and authentication line before implementation.
The host submits only a validated selected identity and remains usable when the widget is slow, blocked, denied, or unavailable.
A blocked, missing, or unentitled provider produces a useful explicit failure rather than a blank surface or fabricated result.
No server credential, bearer value, precise private fixture, or provider response body appears in client bundles, logs, screenshots, or test artifacts.
Resources, listeners, sessions, processes, or requests stop cleanly when the owning screen, request, or application ends.
Supported status is confirmed
Origins and payloads are validated
Fallback is complete
Keyboard and screen-reader behavior is tested