push: name the account an alert is for !449

merged merged by cmc on 2026-09-20 20:58 UTC · krz/gitbay:push-payload-account into main

Discussion

cmc

The v1.32.0 payload carried path and nothing else. A device token is one install, and an install registers against every account signed in on it, so path alone cannot say which instance a notice came from — two instances can hold the same owner/name, and the alert title is the repository path, which does not disambiguate either.

Found while designing the iOS client half, which registers against every signed-in account. The v1.32.0 spec asserted both halves and they contradict: the payload section fixed path as the only routing key while the app section described multi-account registration.

Adds instance (the instance's site_url) and user (the recipient's username) to the payload — the two values a client keys an account by, so it resolves one before routing. DuePush joins users; no schema change, nothing to migrate.

Tests: a store test asserts the username reaches the queue row, an apns test asserts both payload keys, and the e2e asserts them end to end through a real instance. All three fail against v1.32.0.

Ref #89