- importSubjectContext now rejects a non-string/empty selfApp before verifying. verifyJwt skips the audience check entirely when audience is undefined, so an unvalidated selfApp (the natural shape of currentAppName(): string | undefined) accepted every token from every app for every audience. - exportSubjectContext now rejects a non-string/empty targetApp, so an array can no longer mint one token valid at multiple apps. - Both directions now reject a present-but-non-string tenant id instead of silently dropping it (was: callee reads missing tenantId as global/unscoped -> cross-tenant exposure). - importSubjectContext now requires exp to be present and independently bounds accepted token age via a new maxAge/ImportOptions.maxAgeSeconds (default 300s), so a caller cannot mint a long-lived token via a huge ttlSeconds and have it honoured indefinitely. - SubjectContext.callerApp doc now states it is self-asserted (the signing secret is workspace-wide) and must never be an authz input. - index.ts also exports the new ImportOptions type. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
33 lines
956 B
TypeScript
33 lines
956 B
TypeScript
/**
|
|
* @wrnexus/rpc — typed request/response between workspace apps.
|
|
*
|
|
* A contract lives in the workspace's shared package and is imported by both
|
|
* sides: the callee `implement`s it, the caller gets a typed proxy. Types flow
|
|
* through a normal import, so there is no code generator and no generated file
|
|
* to go stale.
|
|
*/
|
|
|
|
export type {
|
|
AnyProcedures,
|
|
InferInput,
|
|
InputSchema,
|
|
InferProcedureInput,
|
|
InferProcedureOutput,
|
|
ProcedureDef,
|
|
ServiceContract,
|
|
ServiceResult,
|
|
} from "./types.ts";
|
|
|
|
export { RPC_ERROR_CODES, ServiceError, failure, isRetryableStatus, success } from "./errors.ts";
|
|
export type { RpcErrorCode, ToResultOptions } from "./errors.ts";
|
|
|
|
export { defineService, procedure, ProcedureBuilder } from "./contract.ts";
|
|
|
|
export {
|
|
RPC_IDENTITY_HEADER,
|
|
exportSubjectContext,
|
|
importSubjectContext,
|
|
rpcSecret,
|
|
} from "./identity.ts";
|
|
export type { ExportOptions, ImportOptions, SubjectContext } from "./identity.ts";
|