Developer reference
Layouts and providers
Understand public/private shells, asynchronous auth verification and portal privacy.
The root layout supplies global styling and providers. Private layouts add the financial shell. Public surfaces are explicitly identified so they can render without a financial session.
Private reveal sequence
- The auth provider restores and verifies an owned identity.
- Until verification is complete, the private body remains concealed.
- Financial queries run under that identity and generation.
- Fresh owned results can populate inquiry views.
A remembered user object is not enough to reveal private content when verification is unavailable.
History and portals
Browser history can restore retained markup before React finishes a fresh check. The privacy lifecycle must cover the whole private body, including header, sidebar, dialogs, portals and animated content. Do not solve a main-content leak while leaving a portal visible.
A Back navigation or account change requires fresh verification before reveal. Global styling or an onboarding coach must respect that same cloak.
Retire old work
When identity changes, retire private caches, pending UI generations and owned in-memory guide state. A late response or delayed animation from the previous account must not repopulate the new account’s UI.
Verify an integration
Test mounted components during verification loading, verification 503, sign-out, Back and a different-account sign-in. Include an open dialog and any coach portal. Helper tests are useful, but browser restoration has its own timing behavior.
Continue with data fetching and security boundaries.