Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
93 commits
Select commit Hold shift + click to select a range
7c38c64
refactor(deps): replace url-parse with native URL API
Kyzgor Jun 23, 2026
575f1b3
test(enforcer): cover OPA base URL construction and wiring
Kyzgor Jun 23, 2026
f438bc3
ci: pin actions to SHA and run full test suite on PRs
zeevmoney Jun 28, 2026
4868670
test: migrate from AVA to Vitest with event-based waits
zeevmoney Jun 28, 2026
e5f227b
test: add comprehensive unit + e2e coverage across SDK modules
zeevmoney Jun 28, 2026
ebd6ec0
fix(enforcer): send checkAllTenants payload and auth header correctly
zeevmoney Jun 28, 2026
5e29bcc
ci: run unit/integration/module-imports on PR, defer e2e to next PR
zeevmoney Jun 28, 2026
0aec4df
Merge branch 'per-15306/ci-pin-actions-tests-on-pr' into per-15315/vi…
zeevmoney Jun 28, 2026
6524fe1
Merge branch 'per-15315/vitest-event-based-tests' into per-15317/comp…
zeevmoney Jun 28, 2026
f5dffbf
ci: run on all pull requests, not only those targeting main
zeevmoney Jun 29, 2026
329a80c
Merge branch 'per-15306/ci-pin-actions-tests-on-pr' into per-15315/vi…
zeevmoney Jun 29, 2026
9e2ccbd
Merge branch 'per-15315/vitest-event-based-tests' into per-15317/comp…
zeevmoney Jun 29, 2026
fc2529b
ci: pin PDP connection to IPv4 (127.0.0.1) in the backend test run
zeevmoney Jun 29, 2026
b8c69b1
Merge branch 'per-15306/ci-pin-actions-tests-on-pr' into per-15315/vi…
zeevmoney Jun 29, 2026
696f446
Merge branch 'per-15315/vitest-event-based-tests' into per-15317/comp…
zeevmoney Jun 29, 2026
42ad33f
test: make rbac useOpa checks opt-in and widen rebac CI budget
zeevmoney Jun 29, 2026
9ae3a77
Merge branch 'per-15315/vitest-event-based-tests' into per-15317/comp…
zeevmoney Jun 29, 2026
64b288c
test: poll the rbac multi-result reads to remove propagation races
zeevmoney Jun 29, 2026
6ade914
Merge branch 'per-15315/vitest-event-based-tests' into per-15317/comp…
zeevmoney Jun 29, 2026
d721e50
test: register the user attribute used by the ABAC condition set
zeevmoney Jun 29, 2026
a71e7ad
test: widen the ABAC condition-set check budget to 180s
zeevmoney Jun 29, 2026
20b1353
Map all-tenant decisions from the PDP response
zeevmoney Sep 29, 2026
3df9603
Fix per-check context precedence in bulk authorization
zeevmoney Sep 29, 2026
bef5ec8
Preserve PDP HTTP errors separately from transport failures
zeevmoney Sep 29, 2026
2657389
Prevent secret logging and honor JSON log configuration
zeevmoney Sep 29, 2026
6b818cd
Document logging options and PDP error types
zeevmoney Sep 29, 2026
a9be8b7
Fix existing lint warnings in tests
zeevmoney Sep 29, 2026
71a7ad6
Keep the API key out of serialized REST errors
zeevmoney Sep 29, 2026
5cb6dad
Merge the test and CI stack (#131-#133) into the correctness fixes
zeevmoney Sep 29, 2026
c41db7d
Port the correctness tests to Vitest
zeevmoney Sep 29, 2026
bb8e8cd
Update tests that pinned the old SDK behaviour
zeevmoney Sep 29, 2026
184bcbf
Keep yarn test and the release job free of backend tests
zeevmoney Sep 29, 2026
554cf9a
Test on Node 22 and 24 and publish from Node 24
zeevmoney Sep 29, 2026
0d40dec
Skip the environment tests when the key lacks scope
zeevmoney Sep 29, 2026
37fc21f
Resolve zizmor findings in the release workflow
zeevmoney Sep 29, 2026
40affd8
Keep a ported test title line under 100 characters
zeevmoney Sep 29, 2026
8c09d6a
Type-check the tests apart from the published build
zeevmoney Sep 29, 2026
6cfb898
Type the mock transport and logger spies in unit tests
zeevmoney Sep 29, 2026
14d9642
Correct the Vitest config comment and stop backend runs early
zeevmoney Sep 29, 2026
8a6f823
Assert exact request paths in the API unit specs
zeevmoney Sep 29, 2026
394078d
Assert the values API methods return in unit specs
zeevmoney Sep 29, 2026
e8c25ee
Show the scheduled delays when retry delay tests fail
zeevmoney Sep 29, 2026
3aa7d48
Bound waitFor attempts and return the value it accepted
zeevmoney Sep 29, 2026
146913f
Add test cleanup helpers that tolerate only a missing entity
zeevmoney Sep 29, 2026
937bf32
Load the built package through Node in module-import tests
zeevmoney Sep 29, 2026
ad8b401
Merge origin/main into fix/106-remove-url-parse-dependency
zeevmoney Sep 29, 2026
b56a9b2
test(enforcer): move enforcer spec under tests/unit
zeevmoney Sep 29, 2026
de362ac
Update the checkout and setup-node pins
zeevmoney Sep 29, 2026
d74b2fc
Add Dependabot for Actions and let its PRs run unit tests
zeevmoney Sep 29, 2026
3738458
Cancel superseded CI runs only on pull requests
zeevmoney Sep 29, 2026
e5abd86
fix(enforcer): throw PermitError without the value on invalid PDP URL
zeevmoney Sep 29, 2026
62df9ea
Run workflow scripts with nounset and pipefail
zeevmoney Sep 29, 2026
f35c9d3
Pin the runner image and bound every job, step and curl
zeevmoney Sep 29, 2026
a9d4dab
test(enforcer): assert useOpa check URL for both OPA client paths
zeevmoney Sep 29, 2026
8cc5474
test(enforcer): scope the url-parse equivalence claim
zeevmoney Sep 29, 2026
718b6dd
Report the Permit API's error responses in CI
zeevmoney Sep 29, 2026
22fcfd5
Clean up the scoped project and keep assertion errors intact
zeevmoney Sep 29, 2026
b48b267
Keep the project key away from repo code and always delete the env
zeevmoney Sep 29, 2026
77cc2b9
Pin the PDP image and run the rbac useOpa checks in CI
zeevmoney Sep 29, 2026
8cd1098
Pass a project-scoped key to the integration tests in CI
zeevmoney Sep 29, 2026
70ec322
Resolve the remaining zizmor findings in the release workflow
zeevmoney Sep 29, 2026
09b3c85
Make the rbac e2e checks real, scoped and visibly skipped
zeevmoney Sep 29, 2026
358fad7
Drop the release job's unpushed docs commit and lock its install
zeevmoney Sep 29, 2026
f4ce99a
Build only the index bundle with tsup
zeevmoney Sep 29, 2026
ea216bd
Split the rebac e2e flow into steps that fit the test timeout
zeevmoney Sep 29, 2026
920e354
Test waitForSync on the request the SDK sends
zeevmoney Sep 29, 2026
cfbab84
Check local facts right after the write, as the PDP promises
zeevmoney Sep 29, 2026
8b66043
Check both halves of the ABAC rule and verify its cleanup
zeevmoney Sep 29, 2026
2ec6107
Stop the bulk and lists specs from hiding setup and cleanup errors
zeevmoney Sep 29, 2026
f3a86ed
Debug the active spec with Vitest instead of AVA
zeevmoney Sep 29, 2026
4eeb76d
Merge the e2e and integration test fixes
zeevmoney Sep 29, 2026
f323c97
Merge the unit and module-import test fixes
zeevmoney Sep 29, 2026
96c3499
Build and document from the SDK-only tsconfig
zeevmoney Sep 29, 2026
a142d23
Add a random part to the integration test's environment keys
zeevmoney Sep 29, 2026
71ee65e
Show the computed delay when retry backoff tests fail
zeevmoney Sep 29, 2026
362b660
Keep enforcer test lines within the 100-character limit
zeevmoney Sep 29, 2026
801e72a
Keep changed lines within 100 characters
zeevmoney Sep 29, 2026
06f2df6
Declare vite as a devDependency for vitest's peer
zeevmoney Sep 29, 2026
f9ab74a
Give each CI test suite only the keys it needs
zeevmoney Sep 29, 2026
3eb0af1
Tighten ported e2e and unit specs
zeevmoney Sep 29, 2026
b3f7a85
Skip the ABAC decision checks pending PER-16553
zeevmoney Sep 29, 2026
4c72664
Merge #122: replace url-parse with the native URL API
zeevmoney Sep 29, 2026
32abc7d
Merge main into the Node SDK 3.0 release branch
zeevmoney Sep 29, 2026
0a5b69f
Align Node runtimes and secure pnpm installs (PER-16557)
zeevmoney Sep 30, 2026
ce98719
Adopt strict TypeScript and Ox tooling (PER-16558)
zeevmoney Sep 30, 2026
1702729
Fix case-sensitive compiler hosts (PER-16558)
zeevmoney Sep 30, 2026
7bcff24
Rebaseline reviewed OpenAPI contracts (PER-16560)
zeevmoney Sep 30, 2026
a398bcf
Gate dependency security before publication (PER-16559)
zeevmoney Sep 30, 2026
e38e5f8
Fix Actions cooldown configuration (PER-16559)
zeevmoney Sep 30, 2026
669f2e2
Validate PDP response contracts (PER-16562)
zeevmoney Sep 30, 2026
c954857
Measure API and PDP contract coverage (PER-16561)
zeevmoney Sep 30, 2026
2c24e1e
Allow compiler fixture time on shared CI runners (PER-16561)
zeevmoney Sep 30, 2026
efb92c3
Isolate HTTP transport ownership and retries (PER-16563)
zeevmoney Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
36 changes: 0 additions & 36 deletions .eslintrc.json

This file was deleted.

112 changes: 110 additions & 2 deletions .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,111 @@
# Example Contributing Guidelines
# Contributing

This is an example of GitHub's contributing guidelines file. Check out GitHub's [CONTRIBUTING.md help center article](https://help.github.com/articles/setting-guidelines-for-repository-contributors/) for more information.
Install the Node version from `.nvmrc` and pnpm 12.8.1. From the repository root:

```sh
pnpm audit --audit-level=moderate
pnpm install --frozen-lockfile --ignore-scripts
pnpm hooks:install
pnpm verify
```

`verify` runs the frozen dependency check, Oxlint, Oxfmt, strict TypeScript, both module builds,
all local unit, module-import, and tooling tests, and the reviewed API contract inventory. It requires no Permit credentials or Java.
CI uses the same verification command. Use `pnpm fix` for lint fixes and formatting, then rerun
`pnpm verify`. Hooks check files without rewriting them.

The hook installer enables Git's per-worktree configuration and installs prek into the current
checkout's own Git directory. It leaves the shared hook path and sibling worktrees unchanged.
Tool versions are pinned in the pnpm lockfile; Dependabot groups updates with a seven-day delay.
For any future remote prek hooks, use frozen commit hashes and `pnpm exec prek update
--cooldown-days 7 --freeze` when reviewing updates.

## Builds and imports

Authored source is ESM under `src/package.json`. Use `#src/` imports, including type-only imports
where appropriate. The root package keeps its CommonJS metadata because it publishes both
`build/index.js` and `build/index.mjs`. TypeScript emits declarations; a checked AST pass replaces
source aliases with paths that resolve inside the packed package. Do not publish source aliases
or change public entry points as an incidental tooling fix.

TypeScript 7 is the SDK checker and emitter. TypeDoc and the generation guard need a JavaScript
compiler API, so the private `tools/compiler` workspace explicitly owns maintained TypeScript 6
and TypeDoc. The SDK has no runtime dependency on that workspace.

## Tests

Use `pnpm test:unit` for focused unit work and `pnpm test:module-imports` for the built entry points.
Add new source tests beside the code as `*.test.ts`; existing grouped `src/tests` suites can be
extended in place. Mock external boundaries and test malformed input and failures. Demonstrate
that a representative regression fails when its fix is removed.

`pnpm test:codegen` tests the generator guard and local tooling without Java. Regeneration requires
Java 17: `pnpm generate-openapi-client` reads the reviewed committed snapshot and shared configuration,
then validates and normalizes the generated output before replacing it. `pnpm check:openapi` compares
two clean generations with each other and the committed output. The separate `pnpm check:codegen`
guard regenerates the historical fixture using the same pinned generator and configuration.
See [the generation guide](../openapi/README.md) before refreshing the snapshot. Never replace the
historical fixture or change API shapes merely to make a tooling check pass.

`test:integration` and `test:e2e` use a Permit backend. Run them locally only with explicit
authorization. The standard verification command uses local fixtures only.

## API operation and shape evidence

`pnpm check:api-contracts` verifies the local AST inventory, source provenance and exact operation
omission decisions. `pnpm check:api-drift` also compares current public schema documentation with
the pinned snapshots; it makes no backend operation calls. Reports distinguish local integrity,
coverage gaps, the unavailable shared parity target and unmeasured backend behavior. See
[the evidence guide](../api-coverage/README.md) before changing a baseline or exclusion.

## Documentation and changes

Run `pnpm run docs` to generate API documentation, or `pnpm run docs:watch` while editing TSDoc.
Use `pnpm run docs -- --out /absolute/output/path` to inspect output without replacing tracked docs.
Keep generated documentation out of unrelated changes.

Keep changes focused, preserve supported runtime behavior, and describe validation and remaining
limitations in the PR. Check [AGENTS.md](../AGENTS.md) for repository development rules.

## Dependency security

Install [Trivy 0.74.0](https://github.com/aquasecurity/trivy/releases/tag/v0.74.0) for the same
scanner used in CI. The audit runner uses Node built-ins and runs before SDK dependencies install:

```sh
node scripts/audit-dependencies.mjs --locked-only --out security-preinstall
pnpm install --frozen-lockfile --ignore-scripts
pnpm build
pnpm pack --out candidate.tgz --ignore-scripts
pnpm audit:dependencies --artifact candidate.tgz --out security-report
```

The report covers the locked SDK runtime graph, the complete development/tooling workspace,
and two independently resolved consumers of the actual tarball. Runtime dependencies are exact
pins, so the minimum and newest supported direct versions are identical. Both consumer lanes
resolve current compatible transitive versions; neither claims to test the lowest transitive
versions. Adding dependency ranges or peer dependencies requires explicit supported-range lanes.

The pinned pnpm resolver uses a 24-hour release delay and disables scripts. It resolves a consumer
lockfile, audits it, then performs a frozen installation only after that lane passes. Trivy's
runtime dependency graph must match an independent pnpm lock inventory. Empty results, incomplete
inventory, malformed output, process failures and unresolved consumer installs are INVALID.

Exit codes are 0 (PASS), 1 (FAIL: fixable HIGH/CRITICAL findings) and 2 (INVALID: not completed).
All other advisories and registry severity totals remain visible in JSON and Markdown, including
findings without available fixes. Raw scanner output and each consumer lockfile are retained.
Do not add ignored advisory IDs, dependency overrides or scanner suppression files.

CI requires these checks on Node 22.13 and 24.0. The weekly Monday workflow and manual dispatch
publish GitHub summaries and downloadable evidence; repository maintainers review failed runs.
Slack delivery requires a separately authorized destination and is not configured here.
The release job also scans its final tarball immediately before publication with scripts disabled;
it cannot publish if either scanner or consumer lane fails. npm Trusted Publishing requires
Node >=22.14.0 and npm >=11.5.1; the release job validates the npm bundled with its Node 24 runner.
The supported SDK Node floor remains 22.13.0.

Dependabot groups runtime and tooling minor/patch updates, uses `increase`, and waits seven days
(fourteen for majors). Its published support matrix currently lists pnpm through version 10;
pnpm 12 lock updates are not yet verified. Maintainers must review dependency update failures and
apply compatible pinned updates manually until the bot supports this lockfile. The scheduled
security gate does not depend on Dependabot and continues to scan all four trees.
34 changes: 34 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
version: 2
updates:
# Keeps the SHA-pinned actions in .github/workflows current. The PDP image in
# ci.yaml is started with docker run, which Dependabot does not track, so its
# version and digest are bumped by hand.
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
cooldown:
default-days: 7
groups:
github-actions:
patterns:
- '*'
- package-ecosystem: npm
versioning-strategy: increase
directory: /
schedule:
interval: weekly
cooldown:
default-days: 7
semver-major-days: 14
groups:
runtime-dependencies:
dependency-type: production
update-types: [minor, patch]
patterns:
- '*'
development-dependencies:
dependency-type: development
update-types: [minor, patch]
patterns:
- '*'
65 changes: 65 additions & 0 deletions .github/workflows/api-contract-drift.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
name: Published API contract drift

on:
schedule:
- cron: '17 7 * * 1'
workflow_dispatch:

permissions:
contents: read

concurrency:
group: api-contract-drift-${{ github.ref }}
cancel-in-progress: false

defaults:
run:
shell: bash --noprofile --norc -euo pipefail {0}

jobs:
published-contracts:
name: Compare published API contracts
runs-on: ubuntu-24.04
timeout-minutes: 15
steps:
- name: Checkout reviewed SDK
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
env:
npm_config_ignore_scripts: 'true'
with:
run_install: false
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '22.13.0'
cache: pnpm
cache-dependency-path: pnpm-lock.yaml
- name: Audit dependency metadata before installation
timeout-minutes: 3
run: pnpm audit --audit-level=moderate
- name: Install locked tools
timeout-minutes: 5
run: pnpm install --frozen-lockfile --ignore-scripts
- name: Inspect published source drift
timeout-minutes: 3
run: pnpm check:api-drift
- name: Summarize evidence
if: always()
run: |
if [[ -f coverage/api-contracts/report.md ]]; then
cat coverage/api-contracts/report.md >> "$GITHUB_STEP_SUMMARY"
else
printf '%s\n' 'API contract inspection did not complete. Inspect the failed setup step.' >> "$GITHUB_STEP_SUMMARY"
fi
- name: Retain drift evidence
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: api-contract-evidence
path: coverage/api-contracts/
if-no-files-found: error
retention-days: 30
Loading
Loading