- Shipped
- July 11, 2026 at 1:02 AM UTC
- Author
- Kamo
- Commit
- 4c70067
- PortalResumeService: 30-day HMAC token (PRESUME|guid|orgId|exp, keyed off the cluster internal.auth.secret — no new secret); mails RESUME_PORTAL_LINK. - POST /portal/resume/send (visitor's own link), /resume/redeem (token → guid for the portal to rebind as its httpOnly cookie), /resume/recover (lookup by email case-insensitive or exact phone; always acks ok:true — enumeration-safe). - GET /portal/lead: claimed-facts snapshot (exact inverse of applyFacts) so a fresh device rehydrates the funnel from the server-side lead. - PortalUrls extracts the myloan.<root> origin resolution shared with the meet-your-LO email.