Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
715 commits
Select commit Hold shift + click to select a range
ca46e4f
Format auction timeline implementation plan
ChristianPavilonis Sep 4, 2026
02b77de
Improve GPT auction diagnostics observability
ChristianPavilonis Sep 4, 2026
ffc0438
Fix GPT auction diagnostics timing accuracy
ChristianPavilonis Sep 4, 2026
a07d3e4
Merge PR #1121 into rc/202609
ChristianPavilonis Sep 4, 2026
f44de23
Merge remote-tracking branch 'origin/main' into rc/202609
ChristianPavilonis Sep 4, 2026
36620e1
Merge branch 'main' into fix/gpt-first-impression-aps-shell
aram356 Sep 5, 2026
ad25cc6
Correct audit polling and literal slot routing
prk-Jr Sep 7, 2026
9a00731
Merge main into ad-template audit tooling
prk-Jr Sep 7, 2026
fbacb4c
Enable Tokio test utilities on all native targets
prk-Jr Sep 7, 2026
e61b29b
Merge main into rc/202609 and resolve EC snapshot conflicts
prk-Jr Sep 7, 2026
50df69e
Merge branch 'main' into issue-355-liveramp-integration
prk-Jr Sep 7, 2026
630661b
Merge branch 'main' into feature/ts-cli-ad-templates
prk-Jr Sep 7, 2026
5fffe2f
Merge #1054 in rc/202609
prk-Jr Sep 7, 2026
c18e598
Serve browser audit fixtures for every Chrome connection
prk-Jr Sep 7, 2026
4e70178
Merge branch 'main' into fix/gpt-first-impression-aps-shell
ChristianPavilonis Sep 7, 2026
4d3e02d
Merge branch 'main' into aps-renderer-failure-diagnostics
aram356 Sep 7, 2026
c59611e
Persist the tester cookie for 30 days so it survives browser restarts
jevansnyc Sep 7, 2026
221caea
Merge branch 'main' into rc/202609
prk-Jr Sep 8, 2026
9d69191
Merge branch 'main' into feature/ts-cli-ad-templates
prk-Jr Sep 8, 2026
5cefd43
Fix browser fixtures and share settle budget
prk-Jr Sep 8, 2026
6f133cc
Merge origin/main into feat/request-phase-timing
jevansnyc Sep 8, 2026
bcc1475
Bound route templates by allowlist and harden the telemetry config su…
jevansnyc Sep 8, 2026
a152367
Address round-3 telemetry robustness findings
jevansnyc Sep 8, 2026
237a99f
Merge branch 'main' into fix/gpt-first-impression-aps-shell
aram356 Sep 8, 2026
6b36f92
Merge branch 'main' into aps-renderer-failure-diagnostics
aram356 Sep 8, 2026
c5b038d
Merge branch 'main' into issue-355-liveramp-integration
aram356 Sep 8, 2026
32e99cc
Clarify GPT auction diagnostics evidence
ChristianPavilonis Sep 8, 2026
0d3aa14
Preserve GPT settle budget and report skipped post-scroll waits
prk-Jr Sep 9, 2026
719e566
Merge remote-tracking branch 'origin/main' into feature/ts-cli-ad-tem…
prk-Jr Sep 9, 2026
dfc19e6
Adapt ad-template diagnostics to provider maps and secret references
prk-Jr Sep 9, 2026
6f2ec06
Merge branch 'main' into issue-355-liveramp-integration
prk-Jr Sep 9, 2026
d269ff8
Fail closed on late CMPs and legacy TCF consent for managed User IDs
prk-Jr Sep 9, 2026
bada61d
Merge branch 'main' into rc/202609
prk-Jr Sep 9, 2026
26be91a
Merge remote-tracking branch 'refs/remotes/origin/pr/1154' into rc/20…
ChristianPavilonis Sep 9, 2026
890c2de
Avoid no-op EC pull-sync KV work
ChristianPavilonis Jul 13, 2026
4e9a01e
Address pull-sync marker review feedback
ChristianPavilonis Sep 8, 2026
beee948
Make EC withdrawal tombstones idempotent
ChristianPavilonis Jul 13, 2026
1cc335b
Prevent stale misses from refreshing EC tombstones
ChristianPavilonis Sep 3, 2026
fe13e1d
Group batch sync mappings by EC ID
ChristianPavilonis Jul 13, 2026
aee5bf6
Remove legacy consent KV persistence
ChristianPavilonis Jul 13, 2026
eb0ffdc
Merge branch 'rc/202609' of github.com:IABTechLab/trusted-server into…
ChristianPavilonis Sep 9, 2026
9d0833e
Reduce EID KV write conflicts
ChristianPavilonis Sep 9, 2026
a5aad79
Preserve EID sync state after KV conflicts
ChristianPavilonis Sep 9, 2026
01caf25
Address first-impression review feedback
ChristianPavilonis Sep 9, 2026
129f4d7
Merge branch 'main' into issue-355-liveramp-integration
prk-Jr Sep 10, 2026
cacfb71
Merge branch 'main' into feature/ts-cli-ad-templates
prk-Jr Sep 10, 2026
66da806
Preserve managed IDs and await CMP discovery
prk-Jr Sep 10, 2026
3c1b2dd
Merge branch 'main' into worktree-tester-cookie-max-age
aram356 Sep 10, 2026
0c390c3
Merge branch 'main' into aps-renderer-failure-diagnostics
aram356 Sep 10, 2026
20debdf
Merge branch 'main' into spec/mobile-ad-render-trace-endpoint
prk-Jr Sep 10, 2026
384d8e0
Merge origin/main into rc/202609
ChristianPavilonis Sep 10, 2026
4123f92
Merge PR #823 into rc/202609
ChristianPavilonis Sep 10, 2026
166ce31
Merge PR #1052 into rc/202609
ChristianPavilonis Sep 10, 2026
9ab611c
Merge PR #1054 into rc/202609
ChristianPavilonis Sep 10, 2026
9218abc
Merge PR #1074 into rc/202609
ChristianPavilonis Sep 10, 2026
10121c8
Merge PR #1079 into rc/202609
ChristianPavilonis Sep 10, 2026
3797f2b
Resolve merge follow-up issues
ChristianPavilonis Sep 10, 2026
2e189f6
Merge PR #1157 into rc/202609
ChristianPavilonis Sep 10, 2026
9b48049
Fix release candidate CI
ChristianPavilonis Sep 10, 2026
a955163
Avoid no-op EC pull-sync KV work
ChristianPavilonis Jul 13, 2026
4bd7ada
Address pull-sync marker review feedback
ChristianPavilonis Sep 8, 2026
d95f684
Fix accidental Prebid Server stored-request demand
ChristianPavilonis Sep 10, 2026
7183c8d
Protect config diagnostics and preserve GPT polling time
prk-Jr Sep 11, 2026
24ac93f
Sanitize generation errors and stabilize the budget fixture
prk-Jr Sep 11, 2026
4368165
Fail closed on unsettled CMP and match Prebid's name resolution
prk-Jr Sep 11, 2026
ae1c472
Address remaining pull-sync marker review feedback
ChristianPavilonis Sep 11, 2026
3d47d41
Make EC withdrawal tombstones idempotent
ChristianPavilonis Jul 13, 2026
09f1bf0
Prevent stale misses from refreshing EC tombstones
ChristianPavilonis Sep 3, 2026
91558be
fix(ec): address tombstone review feedback
ChristianPavilonis Sep 11, 2026
b9c6862
Merge branch 'main' into worktree-tester-cookie-max-age
aram356 Sep 11, 2026
cbbdd04
Honor EdgeZero app config store default
ChristianPavilonis Jul 9, 2026
3a1b677
Address app config review feedback
ChristianPavilonis Aug 17, 2026
42a1ef8
Address remaining config review feedback
ChristianPavilonis Aug 20, 2026
06317ad
Address remaining Fastly config review feedback
ChristianPavilonis Aug 21, 2026
5850f5d
Address final app config review feedback
ChristianPavilonis Aug 24, 2026
95b12a5
Merge branch 'main' into feature/ts-cli-ad-templates
aram356 Sep 11, 2026
282d78b
Merge branch 'main' into spec/mobile-ad-render-trace-endpoint
prk-Jr Sep 14, 2026
adebcb5
Fix managed ID ownership and CMP recovery
prk-Jr Sep 14, 2026
bfe8685
Merge main and preserve host lint guidance
prk-Jr Sep 14, 2026
069a56c
Protect deploy validation output and complete stable GPT waits
prk-Jr Sep 14, 2026
a5da1b8
Report failed browser navigation before checking redirect origins
prk-Jr Sep 14, 2026
285e003
Merge branch 'main' into aps-renderer-failure-diagnostics
aram356 Sep 14, 2026
6645bd2
fix(ec): bound withdrawal marker validity
ChristianPavilonis Sep 14, 2026
d0b304e
Add design for closing out issue #852
prk-Jr Sep 15, 2026
960d5c2
Add implementation plan for the predicate split and cache observability
prk-Jr Sep 15, 2026
af22124
Correct the PR 1 plan and spec against the code
prk-Jr Sep 15, 2026
141537e
Name the missing test_observation helper in the plan
prk-Jr Sep 15, 2026
5a0c98d
Restructure issue #852 as a single pull request
prk-Jr Sep 15, 2026
b94df56
Add plan parts 2 and 3: probe, purge, and the readthrough gate
prk-Jr Sep 15, 2026
39402a5
Carry cache outcomes on auction telemetry
prk-Jr Sep 15, 2026
9840218
Declare cache outcome columns on the auction events datasource
prk-Jr Sep 15, 2026
95678c1
Add a publisher test harness with both a template cache and a telemet…
prk-Jr Sep 15, 2026
bb01f94
Split origin shareability out of template eligibility, and record it
prk-Jr Sep 15, 2026
acebfaa
Record the template-cache bypass reason from both sources
prk-Jr Sep 15, 2026
a8e5374
Drop template_cache_state from auction telemetry
prk-Jr Sep 15, 2026
abc3d79
Correct the documented CI gate list
prk-Jr Sep 15, 2026
071121f
Document the cache telemetry caveats and record two implementation fi…
prk-Jr Sep 15, 2026
a1a93d6
Narrow this branch to issue #852's own scope
prk-Jr Sep 15, 2026
1555f90
Apply review findings
prk-Jr Sep 15, 2026
54f0a9e
Add a portable HTTP client to the operator CLI
prk-Jr Sep 15, 2026
6b36645
Add a portable loop-accept fixture origin for probe tests
prk-Jr Sep 15, 2026
68e0c0e
Add ts origin probe-shareability
prk-Jr Sep 15, 2026
d9b6e95
Key template cache entries on the reader-facing URL as well
prk-Jr Sep 15, 2026
cc0ec9a
Add a surrogate-key purge to the template cache trait
prk-Jr Sep 15, 2026
8f423eb
Make the reader-url purge handle independent of query parameter order
prk-Jr Sep 16, 2026
4dcfbe2
Stop the probe confounding two of its own axes
prk-Jr Sep 16, 2026
66b824a
Fail the probe when a cache answered for the origin
prk-Jr Sep 16, 2026
f56a97d
Make the planning documents describe what was actually built
prk-Jr Sep 16, 2026
c1fbc96
Pin ESI mode and reader support as individually necessary
prk-Jr Sep 16, 2026
796354a
Add the admin cache-purge endpoint on Fastly
prk-Jr Sep 16, 2026
028f569
Answer cache purge with 501 on the non-Fastly adapters
prk-Jr Sep 16, 2026
98247d6
Document EdgeZero store selector alignment
aram356 Sep 16, 2026
ca5b4d4
Plan EdgeZero store selector alignment
aram356 Sep 16, 2026
fbeb195
Use canonical Fastly secret store selectors
aram356 Sep 16, 2026
f2b1b39
Consume canonical EdgeZero deployment selectors
aram356 Sep 16, 2026
3416b71
Document deploy-time Fastly store selection
aram356 Sep 16, 2026
501a3a5
Assert cache-purge parity across the three non-Fastly adapters
prk-Jr Sep 16, 2026
02dab06
Add ts cache purge, driving the service's own endpoint
prk-Jr Sep 16, 2026
c1b9aea
Add a purge leg to the local template-cache harness
prk-Jr Sep 16, 2026
8b11630
Model platform cache intent as one enum rather than two flags
prk-Jr Sep 16, 2026
d20ea24
Gate the origin cache bypass on shareability, not on the ad stack
prk-Jr Sep 16, 2026
9e023e1
Put the origin readthrough loosening behind an operator opt-in
prk-Jr Sep 16, 2026
ff66478
Stop a reader's own cache semantics from blocking origin readthrough
prk-Jr Sep 16, 2026
49fffbd
Document origin readthrough, its weaker guarantees, and its rollback
prk-Jr Sep 16, 2026
c5da1c1
Promote the shared template cache out of spike status
prk-Jr Sep 16, 2026
c60468d
Merge branch 'main' into fix/honor-ez-app-config
ChristianPavilonis Sep 16, 2026
66d1b80
Merge branch 'main' into feature/ts-cli-ad-templates
prk-Jr Sep 16, 2026
86c6dde
Merge remote-tracking branch 'origin/main' into rc/202609
ChristianPavilonis Sep 16, 2026
3ee5ef3
Merge remote-tracking branch 'origin/main' into conflict-resolve/issu…
prk-Jr Sep 16, 2026
6ff8e50
Raise the prebid shim size bound for the merged feature set
prk-Jr Sep 16, 2026
9e69cad
Merge PR #1159 into rc/202609
ChristianPavilonis Sep 16, 2026
1039e03
Drop the unverified latency figure and record what was measured
prk-Jr Sep 16, 2026
5503673
Stop the probe judging a bot wall's challenge page
prk-Jr Sep 16, 2026
290fc73
Stop failing axes the origin honestly declares in Vary
prk-Jr Sep 16, 2026
1e89a97
Merge branch 'main' into fix/pbs-stored-requests
ChristianPavilonis Sep 16, 2026
7bdc3d6
Apply full-branch review findings
prk-Jr Sep 16, 2026
76bc65d
Merge branch 'main' into fix/align-edgezero-pr-381
aram356 Sep 16, 2026
bdb68dd
Merge feat/request-phase-timing and resolve auction timeline review f…
jevansnyc Sep 17, 2026
58f8a35
Correct the section 18 status line and give the wrangler ignore its o…
jevansnyc Sep 17, 2026
11d3758
Merge branch 'main' into worktree-tester-cookie-max-age
aram356 Sep 17, 2026
dae88a0
Improve GPT auction diagnostics observability
ChristianPavilonis Sep 4, 2026
30ccab8
Fix GPT auction diagnostics timing accuracy
ChristianPavilonis Sep 4, 2026
563670d
Address GPT diagnostics review feedback
ChristianPavilonis Sep 14, 2026
628ce28
Clarify GPT auction diagnostics evidence
ChristianPavilonis Sep 8, 2026
b316aee
Address GPT diagnostics review feedback
ChristianPavilonis Sep 14, 2026
9b5bb41
Align GPT diagnostics tests with current metadata
ChristianPavilonis Sep 17, 2026
54d33ad
Hide placeholder dimensions from diagnostics overlay
ChristianPavilonis Sep 17, 2026
645d641
Open Fastly stores by logical ID on the EdgeZero PR 381 branch head
aram356 Sep 17, 2026
d3bb29d
Read the Fastly config entry under its logical ID on every target
aram356 Sep 17, 2026
86a3df8
Move the EdgeZero pin to the PR 381 branch head dbb95018
aram356 Sep 18, 2026
2c43347
Move the EdgeZero pin to the PR 381 branch head fba2076a
aram356 Sep 18, 2026
f9d959f
Move the EdgeZero pin to the PR 381 branch head c40ae8d0
aram356 Sep 18, 2026
60bd675
Avoid no-op EC pull-sync KV work
ChristianPavilonis Jul 13, 2026
e7608af
Address pull-sync marker review feedback
ChristianPavilonis Sep 8, 2026
9ef198d
Address remaining pull-sync marker review feedback
ChristianPavilonis Sep 11, 2026
ff6023c
Make EC withdrawal tombstones idempotent
ChristianPavilonis Jul 13, 2026
93a5147
Prevent stale misses from refreshing EC tombstones
ChristianPavilonis Sep 3, 2026
0aefdb4
Group batch sync mappings by EC ID
ChristianPavilonis Jul 13, 2026
a6bb15b
fix(ec): address tombstone review feedback
ChristianPavilonis Sep 11, 2026
cd20b04
Address grouped batch sync review feedback
ChristianPavilonis Sep 11, 2026
8ac70a9
fix(ec): bound withdrawal marker validity
ChristianPavilonis Sep 14, 2026
e9c1733
Remove legacy consent KV persistence
ChristianPavilonis Jul 13, 2026
e68427e
Clarify legacy consent store migration
ChristianPavilonis Sep 11, 2026
b2eedec
Reduce EID KV write conflicts
ChristianPavilonis Sep 9, 2026
7f4bbec
Preserve EID sync state after KV conflicts
ChristianPavilonis Sep 9, 2026
5f12237
Address EID sync review feedback
ChristianPavilonis Sep 11, 2026
bd0b83a
Implement list_keys_with_prefix for the EID conflict test store
aram356 Sep 18, 2026
0ffb942
Merge PR #1052 into rc/202609
aram356 Sep 18, 2026
2ccaaa6
Merge PR #1159 into rc/202609
aram356 Sep 18, 2026
59d9e0a
Merge PR #1054 into rc/202609
aram356 Sep 18, 2026
e663e09
Merge PR #823 into rc/202609
aram356 Sep 18, 2026
713daf8
Rewrite Sourcepoint bodies without Content-Length
ChristianPavilonis Sep 18, 2026
713b271
Move the EdgeZero pin to the PR 381 branch head 4531aeec
aram356 Sep 18, 2026
653c943
Merge PR #1154 into rc/202609
aram356 Sep 18, 2026
3c9d8c0
Move the EdgeZero pin to the PR 381 branch head 7162b7e2
aram356 Sep 18, 2026
589a8e9
Merge PR #1157 into rc/202609
aram356 Sep 18, 2026
9226cfb
Move the EdgeZero pin to the PR 381 branch head 8b506782
aram356 Sep 18, 2026
7d212b7
Move the EdgeZero pin to the PR 381 branch head fd45db1f
aram356 Sep 18, 2026
c7483aa
Move the EdgeZero pin to the PR 381 branch head 6258b6b2
aram356 Sep 18, 2026
9380c12
Move the EdgeZero pin to the PR 381 branch head bb4e0040
aram356 Sep 19, 2026
9297c73
Merge PR #1175 into rc/202609
aram356 Sep 19, 2026
b1d41c5
Move the EdgeZero pin to the PR 381 branch head cf9a96a0
aram356 Sep 19, 2026
2e16309
Merge updated PR #1175 into rc/202609
aram356 Sep 19, 2026
be595ce
Merge branch 'main' into fix/sourcepoint-unknown-length-1088
aram356 Sep 19, 2026
4295039
Move the EdgeZero pin to the PR 381 branch head 119fbf80
aram356 Sep 19, 2026
1e6fc67
Watch only bundle inputs in the trusted-server-js build script
aram356 Sep 19, 2026
ae47b43
Move the EdgeZero pin to the PR 381 branch head 5878eb74
aram356 Sep 19, 2026
76ef421
Merge updated PR #1175 into rc/202609
aram356 Sep 19, 2026
c2aa6be
Merge branch 'main' into spec/mobile-ad-render-trace-endpoint
prk-Jr Sep 19, 2026
d854348
Merge branch 'main' into 852-template-and-origin-caching
prk-Jr Sep 19, 2026
e3f371f
Reconcile mobile trace design contracts
prk-Jr Sep 19, 2026
f3884a0
Fix origin caching and operator safety checks
prk-Jr Sep 19, 2026
a547d44
Reject incomplete origin shareability evidence
prk-Jr Sep 19, 2026
6e9c50c
Select the release manifest in the CLI deploy examples
aram356 Sep 20, 2026
3e8cde2
Update crates/trusted-server-js/lib/src/integrations/prebid/index.ts
ChristianPavilonis Sep 20, 2026
d6fecdf
Move the EdgeZero pin to the PR 381 branch head 12c3215c
aram356 Sep 20, 2026
f222033
Restrict PBS response admission to sent impressions
ChristianPavilonis Sep 20, 2026
488de2c
Merge branch 'main' into spec/mobile-ad-render-trace-endpoint
prk-Jr Sep 21, 2026
14c274c
Clarify mobile trace design contracts
prk-Jr Sep 21, 2026
2de90f3
Resolve caching probe and purge review findings
prk-Jr Sep 21, 2026
c09f9c2
Merge main and preserve cookie cache isolation
prk-Jr Sep 21, 2026
39e045f
Merge branch 'main' into fix/align-edgezero-pr-381
prk-Jr Sep 21, 2026
99743c0
Address stored-request review feedback
ChristianPavilonis Sep 21, 2026
eeea36f
Merge main into rc/202609
prk-Jr Sep 21, 2026
3f03e5a
Merge commit 'refs/pull/901/head' of github.com:IABTechLab/trusted-se…
ChristianPavilonis Sep 21, 2026
a7b19ca
Address remaining GPT diagnostics review feedback
ChristianPavilonis Sep 21, 2026
f951955
Fix cross-adapter GPT diagnostic timing origins
ChristianPavilonis Sep 21, 2026
f22dc56
Preserve EC withdrawal safety on clock failure
ChristianPavilonis Sep 21, 2026
fd290ac
Address app config review feedback and verify store defaults
ChristianPavilonis Sep 21, 2026
65ddf85
Merge branch 'main' into fix/honor-ez-app-config
prk-Jr Sep 22, 2026
25778ba
Merge branch 'main' into 852-template-and-origin-caching
prk-Jr Sep 22, 2026
e23a908
Merge main into rc/202609 after the LiveRamp squash (#1054)
prk-Jr Sep 22, 2026
e58a8d9
Probe bot and prefetch representations, compare cached headers, and k…
prk-Jr Sep 22, 2026
b8461e9
Refuse unparseable purge URLs and limit readthrough to document requests
prk-Jr Sep 23, 2026
cb4318f
Merge branch 'main' into fix/honor-ez-app-config
aram356 Sep 24, 2026
7a82a94
Merge branch 'main' into spec/mobile-ad-render-trace-endpoint
aram356 Sep 24, 2026
dfe3ced
Merge branch 'main' into worktree-tester-cookie-max-age
aram356 Sep 24, 2026
155d3b0
Clarify trace body validation and browser cleanup
prk-Jr Sep 24, 2026
d361b8e
Merge branch 'main' into spec/mobile-ad-render-trace-endpoint
prk-Jr Sep 24, 2026
591b873
Merge branch 'main' into fix/align-edgezero-pr-381
aram356 Sep 24, 2026
a1710a0
Pin EdgeZero to an immutable rev and close the review findings
aram356 Sep 24, 2026
9f18354
Correct origin probe safety checks and address review feedback
prk-Jr Sep 24, 2026
1751342
Merge main and preserve caching and Next.js coverage
prk-Jr Sep 24, 2026
81f702d
Merge main into rc/202609
aram356 Sep 24, 2026
200ab97
Merge PR #1175 into rc/202609
aram356 Sep 24, 2026
8a02066
Merge PR #1154 into rc/202609
aram356 Sep 24, 2026
ea81afe
Merge PR #1137 into rc/202609
aram356 Sep 24, 2026
5b0aa4b
Merge PR #1107 into rc/202609
aram356 Sep 24, 2026
26ccd12
Merge PR #1159 into rc/202609
aram356 Sep 24, 2026
4abf9b0
Merge PR #901 into rc/202609
aram356 Sep 24, 2026
eda2379
Merge PR #1121 into rc/202609
aram356 Sep 24, 2026
9b4a994
Merge PR #879 into rc/202609
aram356 Sep 24, 2026
f2be833
Merge PR #1169 into rc/202609
aram356 Sep 24, 2026
000c452
Drop the unused PlatformKvStore import from the Fastly platform adapter
aram356 Sep 24, 2026
fb2d6d8
Revert "Merge PR #879 into rc/202609"
aram356 Sep 24, 2026
e6b1880
Reflow the GPT diagnostics overlay assertion after the T0 anchor rename
aram356 Sep 24, 2026
3423ce2
Reapply "Merge PR #879 into rc/202609"
aram356 Sep 24, 2026
6c87bfb
Assert the runtime key override the pinned EdgeZero applies
aram356 Sep 24, 2026
4d0ca8d
Merge branch 'main' into fix/sourcepoint-unknown-length-1088
aram356 Sep 26, 2026
bc2f0b7
Merge remote-tracking branch 'origin/main' into rc/202609
ChristianPavilonis Sep 28, 2026
36532ff
Merge PR #1183 into rc/202609
ChristianPavilonis Sep 28, 2026
4552fcf
Fix Sourcepoint HEAD pass-through test
ChristianPavilonis Sep 28, 2026
9e8884b
Merge PR #1183 follow-up into rc/202609
ChristianPavilonis Sep 28, 2026
e5b8ec4
Merge PR [#1173](https://github.com/IABTechLab/trusted-server/pull/11…
dhruv8sh Sep 29, 2026
ae19908
Merge PR [#1176](https://github.com/IABTechLab/trusted-server/pull/11…
dhruv8sh Sep 29, 2026
8222597
Merge PR [#1177](https://github.com/IABTechLab/trusted-server/pull/11…
dhruv8sh Sep 29, 2026
ce94a4a
Merge PR [#1180](https://github.com/IABTechLab/trusted-server/pull/11…
dhruv8sh Sep 29, 2026
799ceaa
Merge PR [#1181](https://github.com/IABTechLab/trusted-server/pull/11…
dhruv8sh Sep 29, 2026
d6cbe44
Merge PR [#1182](https://github.com/IABTechLab/trusted-server/pull/11…
dhruv8sh Sep 29, 2026
0597fa6
Merge main into September release candidate
prk-Jr Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
74 changes: 38 additions & 36 deletions .claude/agents/pr-reviewer.md

Large diffs are not rendered by default.

6 changes: 3 additions & 3 deletions .claude/skills/deploying-trusted-server-to-fastly/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,9 +51,9 @@ accounts and harmless for single-service ones, so prefer it by default.

## Notes

- The `ts` CLI runs from source without installing: `cargo run -p
trusted-server-cli -- config <args>` (binary name `ts`), or install it with
`cargo install --path crates/trusted-server-cli`.
- The `ts` CLI runs from source without installing:
`cargo run -p trusted-server-cli -- config <args>` (binary name `ts`), or
install it with `cargo install --path crates/trusted-server-cli`.
- The app-config store's logical id and blob key are `trusted_server_config`
(`settings_data.rs` `DEFAULT_CONFIG_STORE_ID`, `config_payload.rs`
`CONFIG_BLOB_KEY`); older builds used `app_config`. The override env-var key
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/format.yml
Original file line number Diff line number Diff line change
Expand Up @@ -149,5 +149,11 @@ jobs:
- name: Run Prettier (check)
run: npm run format

- name: Run Prettier (check) — Markdown outside docs/
working-directory: .
run: >-
docs/node_modules/.bin/prettier --config docs/.prettierrc --check
"*.md" ".claude/**/*.md" ".github/**/*.md" "crates/**/*.md" "scripts/**/*.md" "tinybird/**/*.md"
- name: Build with VitePress (fails on dead links)
run: npm run build
4 changes: 4 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -63,3 +63,7 @@ src/*.html
# leftover local build artifacts (node_modules, target, dist) that remain on disk.
/crates/js/
/crates/integration-tests/

# Wrangler config generated by the Cloudflare integration-test harness from
# wrangler.toml at run time; regenerated on every run.
wrangler.integration.generated.toml
39 changes: 20 additions & 19 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -329,14 +329,14 @@ IntegrationRegistration::builder(ID)

## Configuration Files

| File | Purpose |
| --------------------- | ---------------------------------------------------------- |
| `edgezero.toml` | EdgeZero app/platform manifest and logical stores |
| `fastly.toml` | Fastly service configuration and build settings |
| `trusted-server.example.toml` | Source-controlled Trusted Server app-config template |
| `trusted-server.toml` | Operator-owned app config; gitignored; `ts config push` publishes it as an EdgeZero blob envelope |
| `rust-toolchain.toml` | Pins Rust version to 1.95.0 |
| `.env.dev` | Local development environment variables |
| File | Purpose |
| ----------------------------- | ------------------------------------------------------------------------------------------------- |
| `edgezero.toml` | EdgeZero app/platform manifest and logical stores |
| `fastly.toml` | Fastly service configuration and build settings |
| `trusted-server.example.toml` | Source-controlled Trusted Server app-config template |
| `trusted-server.toml` | Operator-owned app config; gitignored; `ts config push` publishes it as an EdgeZero blob envelope |
| `rust-toolchain.toml` | Pins Rust version to 1.95.0 |
| `.env.dev` | Local development environment variables |

---

Expand All @@ -351,6 +351,7 @@ Every PR must pass:
5. JS build and test (`cd crates/trusted-server-js/lib && npx vitest run`)
6. JS format (`cd crates/trusted-server-js/lib && npm run format`)
7. Docs format (`cd docs && npm run format`)
8. Markdown format outside `docs/` (requires `cd docs && npm ci` first): `docs/node_modules/.bin/prettier --config docs/.prettierrc --check "*.md" ".claude/**/*.md" ".github/**/*.md" "crates/**/*.md" "scripts/**/*.md" "tinybird/**/*.md"`; fix with `--write` in place of `--check`

---

Expand Down Expand Up @@ -439,18 +440,18 @@ both runtime behavior and build/tooling changes.

## Key Files

| File | Purpose |
| -------------------------------------------- | ------------------------------------------------- |
| `crates/trusted-server-core/src/integrations/registry.rs` | IntegrationRegistry, `js_module_ids()` |
| `crates/trusted-server-core/src/tsjs.rs` | Script tag generation with module IDs |
| `crates/trusted-server-core/src/html_processor.rs` | Injects `<script>` at `<head>` start |
| `crates/trusted-server-core/src/publisher.rs` | `/static/tsjs=` handler, concatenates modules |
| File | Purpose |
| --------------------------------------------------------- | ---------------------------------------------------- |
| `crates/trusted-server-core/src/integrations/registry.rs` | IntegrationRegistry, `js_module_ids()` |
| `crates/trusted-server-core/src/tsjs.rs` | Script tag generation with module IDs |
| `crates/trusted-server-core/src/html_processor.rs` | Injects `<script>` at `<head>` start |
| `crates/trusted-server-core/src/publisher.rs` | `/static/tsjs=` handler, concatenates modules |
| `crates/trusted-server-core/src/ec/` | EC identity subsystem (generation, consent, cookies) |
| `crates/trusted-server-core/src/cookies.rs` | Cookie handling |
| `crates/trusted-server-core/src/consent/mod.rs` | GDPR and broader consent management |
| `crates/trusted-server-core/src/http_util.rs` | HTTP abstractions and request utilities |
| `crates/trusted-server-js/build.rs` | Discovers dist files, generates `tsjs_modules.rs` |
| `crates/trusted-server-js/src/bundle.rs` | Module map, concatenation, hashing |
| `crates/trusted-server-core/src/cookies.rs` | Cookie handling |
| `crates/trusted-server-core/src/consent/mod.rs` | GDPR and broader consent management |
| `crates/trusted-server-core/src/http_util.rs` | HTTP abstractions and request utilities |
| `crates/trusted-server-js/build.rs` | Discovers dist files, generates `tsjs_modules.rs` |
| `crates/trusted-server-js/src/bundle.rs` | Module map, concatenation, hashing |

---

Expand Down
25 changes: 15 additions & 10 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

12 changes: 6 additions & 6 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -55,12 +55,12 @@ cssparser = "0.36"
derive_more = { version = "2.0", features = ["display", "error"] }
directories = "5"
ed25519-dalek = { version = "2.2", features = ["rand_core"] }
edgezero-adapter-axum = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.8", default-features = false }
edgezero-adapter-cloudflare = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.8", default-features = false }
edgezero-adapter-fastly = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.8", default-features = false }
edgezero-adapter-spin = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.8", default-features = false }
edgezero-cli = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.8" }
edgezero-core = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.8", default-features = false }
edgezero-adapter-axum = { git = "https://github.com/stackpop/edgezero", rev = "12c3215c2637d961a27eefa12e235033fadb4c4a", default-features = false }
edgezero-adapter-cloudflare = { git = "https://github.com/stackpop/edgezero", rev = "12c3215c2637d961a27eefa12e235033fadb4c4a", default-features = false }
edgezero-adapter-fastly = { git = "https://github.com/stackpop/edgezero", rev = "12c3215c2637d961a27eefa12e235033fadb4c4a", default-features = false }
edgezero-adapter-spin = { git = "https://github.com/stackpop/edgezero", rev = "12c3215c2637d961a27eefa12e235033fadb4c4a", default-features = false }
edgezero-cli = { git = "https://github.com/stackpop/edgezero", rev = "12c3215c2637d961a27eefa12e235033fadb4c4a" }
edgezero-core = { git = "https://github.com/stackpop/edgezero", rev = "12c3215c2637d961a27eefa12e235033fadb4c4a", default-features = false }
env_logger = "0.11"
error-stack = "0.6"
esi = "0.7.2"
Expand Down
18 changes: 9 additions & 9 deletions FAQ_POC.md
Original file line number Diff line number Diff line change
@@ -1,38 +1,38 @@
**What is Trusted Server POC?**
The POC or proof of concept is to prove the technical feasibility of managing advertising for publishers on the server. It uses the edge cloud like Fastly, Akamai etc. to initiate ad requests, integrate prebid server, receive ad response and stitch the ad on the server before sending the page to the client browser. In addition it showcases the capabilities to maintain a key-value (kv) store to use critical data needed by a publisher for advertising and the capability to uniquely identify a user agent using a persistent id
The POC or proof of concept is to prove the technical feasibility of managing advertising for publishers on the server. It uses the edge cloud like Fastly, Akamai etc. to initiate ad requests, integrate prebid server, receive ad response and stitch the ad on the server before sending the page to the client browser. In addition it showcases the capabilities to maintain a key-value (kv) store to use critical data needed by a publisher for advertising and the capability to uniquely identify a user agent using a persistent id

**Is this ready for use by publishers?**
NO. It is NOT a version 1.0 and is NOT ready for use by a punisher in its current form.Its a proof of concept (POC). The purpose is to showcase technical feasibility of executing publisher advertising functions server side and initiate industry effort to define and build an MVP or version 1.0 that is ready for use by publishers
NO. It is NOT a version 1.0 and is NOT ready for use by a publisher in its current form. It is a proof of concept (POC). The purpose is to showcase technical feasibility of executing publisher advertising functions server side and initiate industry effort to define and build an MVP or version 1.0 that is ready for use by publishers

**Why did Tech Lab build the Trusted Server POC?**
Today all of the publisher advertising is managed using third party providers, telemetry and capabilities available on the browser. New privacy initiatives and proposals by all major browsers are severely restricting most third party activities and telemetry used in advertising thus making it less and less effective, for e.g. third party cookie deprecation. Moreover, ad blocking is only growing worldwide. Managing ad requests on the edge cloud offers several advantages and better controls to the publisher, for e.g. device and user identification,enabling third parties with better control, managing privacy and improving page performance.

**Will the Trusted Server work for mobile in app advertising?**
The POC is designed for browsers and the initial trusted server focus is to support browser traffic. A second phase will focus on mobile apps.
The POC is designed for browsers and the initial trusted server focus is to support browser traffic. A second phase will focus on mobile apps.

**Is the Trusted Server free?**
YES. The trusted server will be free and open source and offered under Apache 2.0 license terms.

**Does the POC integrate with my CMS?**
As of today, it doesn’t. This is a simple POC where we are hosting the very basic HTML/JS content inside the Trusted Server application itself. We will begin to release modules and reference architecture as the project moves forward. We’d also love contributions from our community on this front!
As of today, it doesn’t. This is a simple POC where we are hosting the very basic HTML/JS content inside the Trusted Server application itself. We will begin to release modules and reference architecture as the project moves forward. We’d also love contributions from our community on this front!

**What is the vision for MVP or version 1.0?**
Tech Lab envisions the MVP to incorporate capabilities to make a valid Open RTB ad request using a prebid server and process the response for native, display and video ads. Our current plan for MVP version is that it can support addressability (user/device signals, ID solutions, other audience and targeting solutions), privacy management (CMP execution, GPP and TCF strings), CMS integration, Publisher Ad server integration and prebid server integration. We look forward to the industry to help develop the MVP definition.
Tech Lab envisions the MVP to incorporate capabilities to make a valid Open RTB ad request using a prebid server and process the response for native, display and video ads. Our current plan for MVP version is that it can support addressability (user/device signals, ID solutions, other audience and targeting solutions), privacy management (CMP execution, GPP and TCF strings), CMS integration, Publisher Ad server integration and prebid server integration. We look forward to the industry to help develop the MVP definition.

**Will Tech Lab build all the capabilities?**
NOT all the capabilities. Tech Lab will build and support core services to enable existing publisher and adtech companies to build their own modules to support publisher advertising capabilities.
NOT all the capabilities. Tech Lab will build and support core services to enable existing publisher and adtech companies to build their own modules to support publisher advertising capabilities.

**Does the Trusteed Server preclude using third party tags?**
No, it does not. You should be able to begin migrating certain modules and parts of your content and experience as you go, without a forklift upgrade. We plan to support server side tagging capabilities to enable third party support.

**Why are you only using two partners in the POC?**
Fastly and Equativ volunteered time and resources to us and they fit the technical needs and requirements for Trusted Server. For the sake of getting to market ASAP, we chose to double down on these two partners. We do not play favorites or have any financial incentive with these two companies and will begin implementing on other partners in the near future. Any ad exchange supporting prebid server requests should already find support. We will prioritize modules for other edge cloud providers based on industry priorities
**Why are you only using two partners in the POC?**
Fastly and Equativ volunteered time and resources to us and they fit the technical needs and requirements for Trusted Server. For the sake of getting to market ASAP, we chose to double down on these two partners. We do not play favorites or have any financial incentive with these two companies and will begin implementing on other partners in the near future. Any ad exchange supporting prebid server requests should already find support. We will prioritize modules for other edge cloud providers based on industry priorities

**How will this project be managed?**
Tech lab has created the ‘Trusted Server Taskforce’ to manage the requirements and roadmap for the project. We will maintain a core engineering team to build based on task force priorities and invite community contributions, especially third party providers to build their tags and modules for publishers.

**How will you support the publishers planning to implement?**
Yes! As of today we will be providing community support on a best effort basis as we scale up the architecture and use cases. We will do our best to respond to inquiries in the Github project as quickly as we can.
Yes! As of today we will be providing community support on a best effort basis as we scale up the architecture and use cases. We will do our best to respond to inquiries in the Github project as quickly as we can.

**How will it work for medium size publishers using managed Word Press hosting (Ghost)?**
Yes. As long as your managed service provider can separate the edge from the CMS, They should be able to run trusted server. Some work may be necessary and we look to the community for contributions in defining and building for it.
Expand Down
Loading
Loading