mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-10-02 20:57:03 +00:00
Implements OpenPRD 0001 through Phase 0 (specification, schemas, example, docs surface) and Phase 1 (local engine, CLI, conformance tests). Schemas (17 contracts, JSON Schema Draft 2020-12, additionalProperties:false) manifest, namespace, entity-type, property, relationship-type, constraint, query, action, entity, claim, source, evidence, changeset, review, approval, event, package — registered in @logicsrc/validators and exported from @logicsrc/schemas under https://logicsrc.com/schemas/openontology/. @logicsrc/openontology - canonical JSON + sha256 package digests; YAML, JSON, NDJSON, and inline authoring all compile to the same bytes, so digests are authoring-agnostic - id profile: compact / IRI / urn with one canonicalization rule, prefix bound by a Namespace object so IRIs reverse unambiguously - validation: schema, graph (domain/range, datatypes, dangling refs), provenance (source-or-firstParty, agent runId, derivation inputs), policy (excerpt limits, licensing, visibility, staleness) and declared constraints; four severities, stable codes, text/json/yaml/markdown - portable triple-pattern query AST: multi-hop, 14 operators, asOf and recordedAsOf, per-status filtering, distinct/order/limit, explanation mode, and enforced depth/binding/row limits - append-only store: claims are immutable; dispute/retract/supersede append status transitions and the effective status is the latest one - change sets: 9 operations, atomic pre-flight, conflict detection on stale base revisions, semantic diff with duplicate-identity warnings and affected-query deltas, per-operation reviewer decisions - policy: agents propose but can never apply — the denial keys on actor type, so every scope plus high confidence plus --yolo still cannot apply; merges need approval, bulk retractions need two, undeclared action side effects are denied - JSON-LD 1.1 export/import with PROV-O aliases and lossy-field reporting - pluggable signature envelope with a jws-ed25519 reference profile and a fail-closed trust policy CLI: logicsrc ontology init|validate|lint|build|inspect, entity, claim, query, changeset, import, export, audit. Reads take --format, writes default to a proposal, exit codes are stable for CI. Example: examples/openontology/ethereum-ecosystem — 12 entity types, 17 relationship types, 63 entities, 169 claims, 25 sources, 31 evidence records, 5 saved queries, every claim lifecycle state, and a pending merge proposal. All data is fictional; the directory is removable without affecting any core test. Docs: docs/openontology{,-governance,-interoperability}.md, a real /openontology route, homepage + nav + sitemap entries, and a root README section. Verification: 112 new tests; full monorepo build and every workspace test pass; conformance bundle (18 valid + 13 invalid fixtures) runs against the published schemas alone; Node.js 25 and Bun 1.3 produce byte-identical digests, revisions, event trails, and query results. Not included (later PRD phases): MCP resources, REST/SSE, Turso adapter, TUI and PWA surfaces, RDF/SHACL mappings, source adapters, governed actions. Refs: prd/0001-add-logicsrc-openontology-spec.md Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
144 lines
4.3 KiB
TypeScript
144 lines
4.3 KiB
TypeScript
import { createPrivateKey, createPublicKey, generateKeyPairSync, sign, verify } from "node:crypto";
|
|
import type { KeyObject } from "node:crypto";
|
|
import type { Signature } from "./types.js";
|
|
|
|
/**
|
|
* Pluggable signature envelope.
|
|
*
|
|
* PRD open question 2 asked whether package signing should start from JWS, a
|
|
* DID proof, or Sigstore. This implementation defines the envelope as the
|
|
* contract and ships ONE reference profile — `jws-ed25519`, detached, over the
|
|
* package digest — so no DID method, wallet, or CA is mandatory (R19). Other
|
|
* providers plug in by implementing this interface.
|
|
*/
|
|
export interface SignatureProvider {
|
|
readonly algorithm: string;
|
|
readonly signer: string;
|
|
readonly keyId?: string;
|
|
sign(payload: string): string;
|
|
verify(payload: string, signature: string): boolean;
|
|
}
|
|
|
|
export interface VerificationResult {
|
|
ok: boolean;
|
|
algorithm: string;
|
|
signer: string;
|
|
reason?: string;
|
|
}
|
|
|
|
const ED25519 = "jws-ed25519";
|
|
|
|
export function createEd25519Provider(options: {
|
|
signer: string;
|
|
privateKey: KeyObject | string;
|
|
publicKey?: KeyObject | string;
|
|
keyId?: string;
|
|
}): SignatureProvider {
|
|
const privateKey =
|
|
typeof options.privateKey === "string" ? createPrivateKey(options.privateKey) : options.privateKey;
|
|
const publicKey = options.publicKey
|
|
? typeof options.publicKey === "string"
|
|
? createPublicKey(options.publicKey)
|
|
: options.publicKey
|
|
: createPublicKey(privateKey);
|
|
|
|
return {
|
|
algorithm: ED25519,
|
|
signer: options.signer,
|
|
keyId: options.keyId,
|
|
sign(payload) {
|
|
return base64url(sign(null, Buffer.from(payload, "utf8"), privateKey));
|
|
},
|
|
verify(payload, signature) {
|
|
try {
|
|
return verify(null, Buffer.from(payload, "utf8"), publicKey, fromBase64url(signature));
|
|
} catch {
|
|
return false;
|
|
}
|
|
}
|
|
};
|
|
}
|
|
|
|
/** Generate a throwaway Ed25519 keypair — used by tests and `init`. */
|
|
export function generateEd25519KeyPair(): { privateKey: KeyObject; publicKey: KeyObject } {
|
|
return generateKeyPairSync("ed25519");
|
|
}
|
|
|
|
/** Sign a package digest, producing the envelope stored in the manifest. */
|
|
export function signDigest(
|
|
digest: string,
|
|
provider: SignatureProvider,
|
|
now: string
|
|
): Signature {
|
|
return {
|
|
algorithm: provider.algorithm,
|
|
signer: provider.signer,
|
|
value: provider.sign(digest),
|
|
created: now,
|
|
...(provider.keyId ? { keyId: provider.keyId } : {})
|
|
};
|
|
}
|
|
|
|
export function verifyDigestSignature(
|
|
digest: string,
|
|
signature: Signature,
|
|
resolveProvider: (signature: Signature) => SignatureProvider | undefined
|
|
): VerificationResult {
|
|
const provider = resolveProvider(signature);
|
|
if (!provider) {
|
|
return {
|
|
ok: false,
|
|
algorithm: signature.algorithm,
|
|
signer: signature.signer,
|
|
reason: `No verifier registered for signer ${signature.signer} (${signature.algorithm})`
|
|
};
|
|
}
|
|
if (provider.algorithm !== signature.algorithm) {
|
|
return {
|
|
ok: false,
|
|
algorithm: signature.algorithm,
|
|
signer: signature.signer,
|
|
reason: `Verifier algorithm ${provider.algorithm} does not match signature ${signature.algorithm}`
|
|
};
|
|
}
|
|
const ok = provider.verify(digest, signature.value);
|
|
return {
|
|
ok,
|
|
algorithm: signature.algorithm,
|
|
signer: signature.signer,
|
|
reason: ok ? undefined : "Signature does not verify against the package digest"
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Trust policy for imported maintainers (R112): a package's signatures are
|
|
* only meaningful against an explicit list of signers you already trust.
|
|
*/
|
|
export function verifyPackageSignatures(
|
|
digest: string,
|
|
signatures: Signature[] | undefined,
|
|
trusted: Map<string, SignatureProvider>
|
|
): { ok: boolean; results: VerificationResult[]; untrusted: string[] } {
|
|
const results: VerificationResult[] = [];
|
|
const untrusted: string[] = [];
|
|
|
|
for (const signature of signatures ?? []) {
|
|
if (!trusted.has(signature.signer)) untrusted.push(signature.signer);
|
|
results.push(verifyDigestSignature(digest, signature, (s) => trusted.get(s.signer)));
|
|
}
|
|
|
|
return {
|
|
ok: results.length > 0 && results.every((r) => r.ok),
|
|
results,
|
|
untrusted
|
|
};
|
|
}
|
|
|
|
function base64url(buffer: Buffer): string {
|
|
return buffer.toString("base64").replace(/\+/g, "-").replace(/\//g, "_").replace(/=+$/, "");
|
|
}
|
|
|
|
function fromBase64url(value: string): Buffer {
|
|
const padded = value.replace(/-/g, "+").replace(/_/g, "/");
|
|
return Buffer.from(padded, "base64");
|
|
}
|