Reference
Isolation and Failure Boundaries
Look up syntax, contracts, layouts, algorithms, and exact behavior.
Per-user renderers are the primary isolation boundary. User identity selects a renderer, the renderer selects an active page, and the active page selects the callback table. A callback message that does not match the current user and page should not be able to invoke another user's component function.
The architecture therefore treats duplicate connections, stale callback IDs, page transitions, and viewport-specific state as renderer-management problems rather than client-rendering problems. The tradeoff fits controlled shells and internal tools where the server is meant to remain the source of truth.
- Callback IDs are scoped by renderer and page, not treated as global capabilities.
- Page transitions clear or replace the active callback surface.
- Screen-size tracking is user-specific, which prevents one viewport from driving another user's layout decisions.
- Connection policy belongs to the server manager rather than to generated markup.