Notifications, webhooks and embedded menu
Distinguish in-site notices, external callbacks and controlled embedding; verify signatures and delivery rather than relying on popups.
Updated
Before you start
- This reference follows current LINK42 pages and permissions. Feature flags, roles, quotas and upstream state govern availability; changing a URL or model name does not bypass authorization.
In-site notifications
Read task/account/business messages. Marking read changes only notice state, not tasks or charges.
| Function / field | Action and purpose | Verification and boundary |
|---|---|---|
| Read state | Filter and inspect related records | Delivery may lag; task/ledger state is authoritative. |
| Preferences | Configure enabled channels | Unconfigured email/browser permissions are not delivery guarantees. |
| Privacy | Sanitize support feedback | Do not expose private URLs, cookies or keys. |
Create and verify webhooks
Select events and a public HTTPS endpoint/signing secret. Verify the original body before processing; an unverified callback is not payment/task evidence.
| Function / field | Action and purpose | Verification and boundary |
|---|---|---|
| Event / URL | Subscribe minimally and validate URL | No private/loopback/insecure bypass of egress policy. |
| Signature / time | Verify original bytes per API reference | Reject invalid/expired messages; signing keys differ from API keys. |
| Duplicates | Process idempotently by event ID | Delivery can repeat or lag; never fulfill twice. |
| Delivery logs | Inspect response/failure/replay | Replay requires authority and receiver idempotency. |
Embedded menu
Embedding supplies the available menu view, not public sharing of private sessions or keys. Configure host, authentication and visible content under product-supported rules.
| Function / field | Action and purpose | Verification and boundary |
|---|---|---|
| Menu entry | Check source and destination | Load only authorized content, not admin APIs in public pages. |
| Session / origin | Respect site/browser policies | Do not disable CSP, certificate validation or authentication. |