Authorization core: capabilities, permissions & passkeys groundwork. The authorization stack lands: trusted-client silent consent, a client capabilities registry with manifest sync and push endpoint, the RBAC+ABAC permission grain and resolver with a live-fetch internal endpoint, instant permissions_changed webhook invalidation, feature-gated auto-migrations, and the passkey credential store + WebAuthn ceremonies.
10 changes:
Capabilities push endpoint
Client capabilities registry and manifest sync
Framework auto-migrations are now gated by enabled features
Internal permissions endpoint (live fetch)
Passkeys groundwork: credential store and WebAuthn library