Orchestrates notifier triggering with deterministic recipient normalization.
Duplicate-trigger contract
When trigger/3 returns {:duplicate, event}, dispatch_after_trigger/4 is INERT
— it does NOT re-drive dispatch for the existing event. This means:
- No new Oban jobs are enqueued.
- No additional
Chimeway.Deliveryrows are planned. - The pre-existing pending deliveries from the first trigger remain in their current state (whether already-dispatched, retrying, or terminal).
If a host application crashes between the event insert committing and the dispatcher
being called, a subsequent re-fire does not recover deliveries from the interrupted
trigger. Recovery requires an explicit operator replay. Operators investigating
"why wasn't this delivered after a duplicate trigger?" should inspect the original
event's deliveries via
Chimeway.Traces.get_trace/1, not at the duplicate.
Payload sanitization
trigger/3 strips @sensitive_keys from persisted event payload and from
notification metadata / render_assigns. Auth-flow keys url, code,
raw_token, and magic_link_url are removed in addition to password,
token, and secret. Identifier-only trigger params remain the primary
contract for integration boundaries.