LinkedIn Import Phase 1: connect, review, stay on your device
Resumer can pull LinkedIn into a draft you review first — your CV stays on your device, not our servers. The feature flag stays off in production until we're ready.
That line is the whole story in one breath. Here's what actually landed, what we left off on purpose, and why.
What shipped (merged to main)
PR #13 — feat: LinkedIn OAuth + paste import (Phase 1) — merged 2026-09-30 (7cb6ca9).
Phase 1 is foundation work:
- OAuth broker —
authorize→ LinkedIn →callback→ short-lived encrypted identity handoff →redeem. The server exchanges the code and passes basic identity. It does not store your CV. The browser never POSTs the resume body. - Review / confirm UI on
/build— you see what's mapped before anything hits the form. Confirm applies viaform.reset; cancel discards. - Optional paste on that screen — Sign In with LinkedIn (OpenID Connect) only returns basic identity (name, and email if you allowed it). It does not include jobs or education. Paste can fill Experience and Education in the browser if you choose.
- Form fix —
defaultValues/resetso import apply actually works. - No new npm dependencies. Proof scripts and fixtures included.
Why the flag is off in production
Import UI and the LinkedIn routes stay behind:
NEXT_PUBLIC_FEATURE_LINKEDIN_IMPORT=true
Exact string true. Anything else — unset, empty, typo — keeps Import hidden. With the flag off, those routes return 404 with feature_disabled and never redirect to LinkedIn.
Production leaves the flag unset. LinkedIn secrets stay optional until we flip it.
Two reasons we didn't turn it on yet:
- OIDC identity alone is too thin for a useful import. Name and email are a start; a CV needs work history and education. LinkedIn's self-serve Sign In product doesn't give us that.
- Paste wasn't reliable enough in testing. We kept the path as optional enrichment, not the main bet.
So Phase 1 ships the broker and the gated UI. The OAuth pieces stay in the repo for a possible future LinkedIn login even if Import stays dark.
Privacy, plainly
Resumer's rule: we don't store your CV on the server.
For this flow that means:
- Server brokers OAuth and a short-lived identity cookie (minutes, encrypted, one-time redeem).
- Editor snapshot around the LinkedIn round-trip lives in
sessionStorageon your device — not sent to us. - Confirm fills the form locally. Cancel restores what you had. Nothing about your resume body is accepted on redeem.
If you care about privacy as much as getting a draft started, that's the point of the design.
What's still parked
Phases 2–4 are not in this merge:
- Phase 2 — localStorage workspace / variants
- Phase 3 — job-description rewrite helpers
- Phase 4 — ATS-oriented checks
We'll pick those up when Import is solid enough to turn on without apologizing.
How to try it (when the flag is on)
Locally: set NEXT_PUBLIC_FEATURE_LINKEDIN_IMPORT=true, plus the four server vars (LINKEDIN_CLIENT_ID, LINKEDIN_CLIENT_SECRET, LINKEDIN_REDIRECT_URI, LINKEDIN_SIGNING_SECRET). LinkedIn app needs Sign In with LinkedIn using OpenID Connect and scopes openid profile email. Redirect URI must match.
Until then, live site: Import stays hidden. That's intentional.