The gateway decides whether a TV may keep running its current build.
Clients send X-Memby-Version on every request and ask GET /v1/update on
each launch; the verdict is none, optional or mandatory.
- internal/appupdate holds the decision as pure, tested logic: below
minimumVersion is mandatory, below latestVersion is optional.
- Admin page gains an App updates section — latest version, APK URL,
notes, and a "Require this update" toggle that sets the forced floor.
- Client shows a dismissable prompt for optional, and a full-screen
panel that swallows Back for mandatory. Instructions say what the
system installer will ask before it asks.
Two safeguards: a client that cannot report its version is never forced,
and the client ignores a verdict with no download URL, so a
half-configured policy cannot produce an unblockable screen with a dead
button. An unreachable gateway shows nothing.
The verdict is deliberately not part of /v1/home: that payload is cached
per user, while this answer depends on the requesting client's version.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>