docs: implementation plan for the inter-app communication system
Eleven TDD tasks covering phase 1: contract and immutable procedure builder, error classification, the signed subject-context token, the Transport seam with an in-process transport for tests, implement() with fail-closed identity and permission checks, the typed client proxy, the HTTP transport, router discovery of app/services, and the mounted endpoint with its two independent external-access guards. Phases 2-4 (retry and circuit breaking, app-to-app streaming, identity for pubsub and queue) are documented as deferred with the reason each needs its own design pass. Task 10 is called out as the highest-risk: if /__wrnexus/rpc/* is reachable from the public internet, every permission check in the workspace is bypassable, so the plan requires the gateway block and the app-side check to be verified as working independently of each other. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in: