master
${ noResults }
164 Commits (ca01324f67c29b57b762ef7940f32ec302d07029)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
f62020e687 |
Add Orca.commit() — freeze the action graph
`commit()` flips a one-way `committed` flag; subsequent `onEvent()` calls throw `OrcaFrozenError` (code `ORCA_ERR_FROZEN`). It is idempotent, does not run `validate()` implicitly, and does not disturb already-registered actions, in-flight runs, or detach functions returned before the freeze. `dispose()` keeps precedence over the frozen guard. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
c996c90dc8 |
Honor compensate: invoke compensators LIFO when a run aborts
Fourth batch of v1 features. With this, OrcaAction.compensate moves
from accepted-and-ignored to a real Saga-style rollback hook: when a
run aborts (OrcaFatal, ORCA_ON_ERROR_ABORT_RUN, or trace-aborted), the
engine walks back through every action that previously completed in
success and invokes its compensator before the FINALLY stage runs.
Engine semantics:
- During the action loop, when an action returns success and has
declared `compensate`, push { action, payload } onto a LIFO stack
(compensable[]). Stage FINALLY actions are not compensable —
FINALLY is the cleanup pass itself.
- On entry to the FINALLY stage with aborted=true and
compensable.length > 0, walk the stack in reverse. Each
compensator gets a fresh AbortController (the run controller is
already aborted) and an OrcaActionContext whose emit() returns
null — compensations do not fan out new events, they roll back.
- Compensations are best-effort: a thrown compensator is recorded as
ORCA_ACTION_STATUS_ERROR but the next compensation in the chain
still runs. v1 chooses best-effort over fail-fast because rolling
back N-1 entries when one of them failed is more useful than
rolling back zero.
- FINALLY actions run AFTER compensations, in normal stage order.
Conceptual order on abort:
action loop → compensation phase → FINALLY → run trace recorded.
- Compensations appear in OrcaRunResult.compensations[], a separate
field from actions[]. The original action's record stays in
actions[] with its original success status; the compensator's
record lives only in compensations[]. This keeps the run trace
accurate (the action did succeed; it was just compensated later).
- Diagnostics: orca.compensation.started (DEBUG),
orca.compensation.completed (DEBUG), orca.compensation.failed
(ERROR). All carry runId, actionId, eventId, traceId, depth.
- Compensation does NOT trigger for PARTIAL runs (CONTINUE-onError
actions that errored without aborting) or TIMEOUT-only runs that
didn't abort. The semantic is "all-or-nothing rollback for
aborted runs", not "partial cleanup".
OrcaRunResult gains a `compensations: readonly OrcaActionRun[]` field
(empty array when no compensation ran).
Tests (+10 in a new "v1 — compensate" describe block):
- does not invoke compensate when the run completes successfully
- invokes compensate of a previously successful action when the run
aborts (the simplest happy path)
- does not invoke compensate of an action that errored itself
- runs compensations in LIFO order (with three compensators)
- runs compensations even when OrcaFatal aborts the run
- continues with remaining compensations even if one throws
(best-effort, the failing compensator's status is ERROR but
earlier and later ones still ran)
- runs FINALLY actions after compensations (order: ['compensate',
'finally'])
- does not invoke compensate when a CONTINUE-onError action errors
(PARTIAL run, no abort)
- emits orca.compensation.{started,completed,failed} diagnostics
- passes the original event payload to compensate
- emits inside ctx during compensation are dropped (return null)
The legacy "accepts compensate without invoking it" test from the v0
forward-compat block was deleted; v0 promise is now v1 reality. The
case it asserted (compensate of a failing action is not invoked) is
now covered explicitly by the new "does not invoke compensate of an
action that errored itself" test.
Verification: 1402/1402 vitest tests pass (92 in orca, +10 from this
commit on top of 82 from previous v1 commits).
README updated: compensate moved from "Roadmap v1" to "Ya en el motor
(de v1)". Remaining v1 items: commit() configuration freeze, queue
policies (commit/replace), transaction groups, parallel,
payload-bearing tokens, fan-in, bus interception (Option B), and
createActiveOrca() reactive wrapper.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
7aebe7c673 |
Add Orca.validate() — static graph analysis of registered actions
Third batch of v1 features. With the gates honored, configuration
mistakes (orphan tokens, dependency cycles, ordering bugs) became
silently fatal: the action skips/blocks at runtime with a misleading
"reason" like "after-not-met:foo" without telling the developer that
"foo" is never produced by anything. validate() catches those before
the first event arrives.
API: EngineOrca.validate(): OrcaValidateResult
- ok: false iff any issue has severity 'error'
- issues: array of OrcaValidateIssue { kind, severity, event,
actionId?, token?, cycle?, message }
- Never throws. Read-only over the registered set; safe to call
multiple times during config; engine does not gate runs on result.
Issue kinds:
- unsatisfiable-after (ERROR) — an action's `after: [T]` is not
produced by any earlier action in canonical order. Action would
always skip at runtime.
- orphan-unless / orphan-abort-on (WARN) — gate token has no
upstream producer. May be deliberate (forward-compat / typo
guard); demoted to warning so `ok` stays true.
- dependency-cycle (ERROR) — actions block on each other through
`after` / `provides`. DFS over an action-level adjacency map
(A → set of action ids it depends on); cycles deduped via a
canonical fingerprint (rotated to lexicographically smallest id
first).
Canonical order matters: actions are sorted by (stage, registeredAt)
so the validator's "did any earlier action provide T" matches what
the engine does at runtime. Concrete consequences:
- A producer registered AFTER the consumer in the same stage is
NOT considered upstream — runtime would skip the consumer, and
validate() reports it.
- A producer in a LATER stage (e.g. POST when consumer is MAIN)
is NOT considered upstream either.
Tests (+11):
- empty engine returns { ok: true, issues: [] }
- happy path: provider in earlier stage satisfies consumer
- reports unsatisfiable-after for missing token
- reports unsatisfiable-after when producer registered AFTER consumer
in the same stage (subtle ordering bug)
- reports unsatisfiable-after when producer is in a later stage
- reports orphan-unless as warning (ok stays true)
- reports orphan-abort-on as warning
- detects direct 2-action cycle
- detects indirect 3-action cycle (cycle.length === 4 with closure)
- warnings do not flip ok to false
- issues are isolated per event (cross-event tokens don't satisfy
each other)
Constants exported from $orca:
ORCA_VALIDATE_UNSATISFIABLE_AFTER
ORCA_VALIDATE_ORPHAN_UNLESS
ORCA_VALIDATE_ORPHAN_ABORT_ON
ORCA_VALIDATE_DEPENDENCY_CYCLE
ORCA_VALIDATE_SEVERITY_ERROR
ORCA_VALIDATE_SEVERITY_WARN
Types exported: OrcaValidateIssue, OrcaValidateIssueKind,
OrcaValidateResult, OrcaValidateSeverity.
README updated: validate() moved from "Roadmap v1" into "Ya en el motor
(de v1)". Remaining v1 items: compensate, commit() configuration freeze,
queue policies (commit/replace), transaction groups, parallel,
payload-bearing tokens, fan-in, bus interception (Option B), and
createActiveOrca() reactive wrapper.
Verification: 1392/1392 tests pass (82 in orca, +11 from this commit).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
79d6d1f776 |
Honor after/unless/abortOn gates in the orca engine
Second batch of v1 features. With this, the `provides`/`emits` token
infrastructure that has lived in OrcaAction since v0 finally has
control-flow consequences: tokens emitted by one action gate the
acceptance of subsequent actions in the same run.
Gate semantics:
- `unless: T[]` — declared on actions that should not run again if
a sibling action already produced their precondition (idempotency
guard). When any token in `unless` is present, the action is
SKIPPED with reason `unless-triggered:<token>`.
- `abortOn: T[]` — declared on actions that must halt when an upstream
flagged danger. When any token in `abortOn` is present, the action
is BLOCKED (distinct from skipped) with reason
`abort-on-triggered:<token>`.
- `after: T[]` — declared on actions whose work depends on tokens
emitted by upstream actions. When any required token is missing,
the action is SKIPPED with reason
`after-not-met:<missing1>,<missing2>,…`.
Evaluation order is deliberate: unless first (idempotency), abortOn
second (halt signal), after third (weakest reason to skip). The first
gate that fires short-circuits the action; later gates are not
evaluated. The FINALLY stage bypasses all gates so cleanup work runs
unconditionally.
Engine changes:
- New evaluateGates(action, tokens, now) helper produces a
synthesized OrcaActionRun when a gate fires, or null when the
action should proceed.
- executeRun calls evaluateGates() right after the trace-aborted
short-circuit and before the per-action AbortController is set up.
Gated actions emit either ACTION_SKIPPED or ACTION_BLOCKED
diagnostics and never reach runAction().
- The "run aborted between stages" path now also emits an
ACTION_BLOCKED diagnostic with reason 'run-aborted', so blocked
actions are observable in logs regardless of cause.
- OrcaActionRun.interruptedReason renamed to OrcaActionRun.reason —
the field carries gate, reentry, or authored reasons uniformly
across SKIPPED, BLOCKED, INTERRUPTED. The status determines what
kind of reason it is.
New constants exported from $orca:
- ORCA_GATE_REASON_AFTER_NOT_MET
- ORCA_GATE_REASON_UNLESS_TRIGGERED
- ORCA_GATE_REASON_ABORT_ON_TRIGGERED
- ORCA_GATE_REASON_RUN_ABORTED
- ORCA_DIAGNOSTIC_EVENTS.ACTION_BLOCKED
Tests (+11):
v1 — after gate (3):
- skips an action whose `after` token is missing
- runs the action when every `after` token has been emitted
- reports every missing token in the reason when partially met
v1 — unless gate (2):
- skips an action when any `unless` token is present
- runs the action when no `unless` token is present
v1 — abortOn gate (3):
- blocks an action when an abortOn token is present
- runs the action when no abortOn token is present
- emits orca.action.blocked diagnostic with the abortOn reason
v1 — gate precedence and FINALLY bypass (3):
- unless wins over after when both would short-circuit
- abortOn wins over after when both would short-circuit
- FINALLY stage bypasses gates so cleanup always runs
The legacy "accepts after/unless/abortOn without enforcing" forward-
compat tests from the v0 ignored-fields block are removed; v0 promise
is now v1 reality. The orcaInterrupted-reason test was updated to read
the renamed `reason` field.
Verification: 1381/1381 tests pass (71 in orca, +11 from this commit
on top of 63 from the previous v1 commits).
README updated: gates moved from "Roadmap v1" to "Ya en el motor (de
v1)". Remaining v1 items: compensate, commit/replace queue policies,
transaction groups, parallel, payload-bearing tokens, fan-in, bus
interception (Option B), validate()/commit() static graph validation,
and createActiveOrca() reactive wrapper.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
793767fe0d |
Honor actionTimeoutMs and OrcaFatal in the orca engine
First batch of v1 features. These were accepted in the public surface
since v0 but the engine ignored them — the documents called out
ORCA_RESULT_TIMEOUT as never produced, OrcaFatal as treated like
error. Now both are real.
actionTimeoutMs:
- In runAction, if action.actionTimeoutMs > 0, race the action's
promise against a timer scheduled on the injected TimerScheduler.
When the timer wins, it aborts the action's signal and resolves
with orcaTimeout(timeoutMs). The action's promise keeps running
in the background; the run trace records the timeout regardless.
- Each action gets its own AbortController, chained to the run-level
controller via an addEventListener('abort') hop. A timeout aborts
just that action; sibling actions in the same stage proceed.
- Diagnostic orca.action.timeout fires with timeoutMs and the usual
envelope identity.
- Run status: any TIMEOUT action puts the run in ORCA_RUN_TIMEOUT.
OrcaFatal:
- orcaFatal(error) result now maps to ORCA_ACTION_STATUS_FATAL (was
silently mapped to ERROR).
- In executeRun, FATAL status aborts the run unconditionally — it
overrides the action's onError policy. CONTINUE-flagged actions
that return fatal still abort.
- The FINALLY stage continues to run after a fatal abort.
- Diagnostic orca.action.fatal fires at LogLevel.FATAL with a
fatal: true marker and the error payload.
- Run status: any FATAL action puts the run in ORCA_RUN_FATAL.
Run-status precedence is now explicit:
FATAL > TIMEOUT > ABORTED > INTERRUPTED > PARTIAL > SUCCESS
Tests (+9):
v1 — actionTimeoutMs (5):
- produces ORCA_RESULT_TIMEOUT when action exceeds its timeout
- runs to completion when action finishes before timeout
- aborts the action signal when the timeout fires (cooperative
cancellation observable inside the action)
- emits orca.action.timeout diagnostic with timeoutMs
- lets later actions in the same stage proceed after a timeout
v1 — OrcaFatal (5):
- maps OrcaFatal to ORCA_ACTION_STATUS_FATAL
- aborts the run regardless of onError policy when fatal fires
- still runs FINALLY stage after a fatal abort
- emits orca.action.fatal diagnostic with fatal: true
- precedence: fatal beats every other status
The legacy "accepts actionTimeoutMs without enforcing timeout" test
from the v0 forward-compat block was removed; v0 promise is now v1
reality. Also dropped the equivalent OrcaFatal-as-error compatibility
behavior — fatal is now a distinct status across the engine.
Tests use the real createEngineTimers() in the timeout block so the
fake timer's not-implemented schedule() doesn't interfere; the existing
fake timer continues to serve every other test that doesn't rely on
actual scheduling.
Verification: 1373/1373 tests pass (63 in orca, +9 from this commit on
top of the 54 from the v0-kernel + verification commits).
README updated: actionTimeoutMs and OrcaFatal moved out of "Roadmap v1"
into a "Ya en el motor (de v1)" section. Remaining v1 items: compensate,
after/unless/abortOn gates, commit/replace queue policies, transaction
groups, parallel, payload-bearing tokens, fan-in, bus interception
(Option B), validate()/commit() static graph validation, and
createActiveOrca() reactive wrapper.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
0f52fdfce6 |
Close orca v0 verification gaps left by the previous commit
The previous commit added reentry guards and ctx.emit() but the tests
only covered the most visible behaviors. Honest audit surfaced six
untested paths:
- orcaInterrupted() helper round-trip into ORCA_RUN_INTERRUPTED
- maxEventsPerTrace guard (only maxDepth and repeatedEventLimit had
dedicated tests)
- the emit/blocked/aborted/interrupted diagnostic events with their
enriched meta (eventId/traceId/parentEventId/depth/emittedByAction)
- dispose() while a trace has live work
- the ORCA_RUN_INTERRUPTED status appearing on actual runs (the
previous "abort-trace" test only checked run count)
- run-scoped diagnostics carrying envelope identity consistently
Adds 7 tests across the existing v0 envelope/reentry block plus a new
diagnostics block:
envelope/reentry block (+3):
- action that returns orcaInterrupted maps to interrupted status
and run (validates orcaInterrupted helper end-to-end)
- blocks the (N+1)th event in a trace when N = maxEventsPerTrace
- the existing abort-trace test gained an assertion that the
child run completed before the abort took effect, plus a
follow-up bus publish to verify the trace is sealed.
diagnostics block (+5):
- emits orca.event.emitted carrying traceId, parentEventId, depth
and emittedByAction
- emits orca.reentry.blocked when a guard rejects an emit
- emits orca.trace.aborted when policy is abort-trace
- emits orca.action.interrupted when an action returns
orcaInterrupted
- every run-scoped diagnostic carries eventId/traceId/depth
consistently across run.started / action.started / run.completed
Test infrastructure: introduces createCapturingLogger() that intercepts
the Logger interface and pulls structured DiagnosticEntry rows from
the catalogued log routing in libs/logger/diagnostics.ts. The
input.context.diagnostic shape is documented enough to be a stable
public test interface without reaching into internals.
Total: 1364/1364 vitest tests pass (54 in orca, +7 from this commit on
top of the 10 from the kernel commit).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
feacd46c62 |
Promote orca v0 from callback runner to orchestration kernel
Implements the v0-kernel design captured in docs/orca_minds.txt: the
engine now carries every event through an internal envelope, exposes
trace identity to actions, and bounds derived-event chains through
configurable reentry guards. The previous engine was effectively a
callback runner with stages; this commit turns it into a runtime that
can answer "where does this event come from, how deep is it, and when
should I stop?" without polluting user-defined payloads with runtime
metadata.
New public surface:
- OrcaEnvelope<TPayload> + OrcaEventMeta (eventId, traceId,
parentEventId, parentRunId, emittedByAction, depth, stack,
publishedAt, dedupeKey)
- OrcaActionContext gains eventId / traceId / parentEventId / depth
plus emit(event, payload, options?) -> OrcaEventId | null
- OrcaResult adds OrcaInterrupted (with orcaInterrupted() helper)
- OrcaActionRun.status and OrcaRunResult.status add 'interrupted'
- OrcaRunResult exposes eventId / traceId / parentEventId / depth
- OrcaReentryOptions on EngineOrcaOptions: maxDepth (16),
maxEventsPerTrace (128), repeatedEventLimit (2),
repeatedEventPolicy (skip / abort-trace / error)
- Constants for reentry policies and reasons; OrcaReentryError class
Engine semantics:
- Bus publishes are roots: fresh traceId, depth=0, no parent. They
never enter the reentry counters.
- ctx.emit() builds a child envelope inheriting the parent's traceId
and incrementing depth. The child is enqueued, never executed
inline.
- Reentry guards apply only to derived envelopes. Crossing maxDepth,
maxEventsPerTrace, repeatedEventLimit, or matching a previous
dedupeKey triggers the configured policy. Skip blocks just that
envelope; abort-trace marks the trace and skips every queued event
that belongs to it; error throws OrcaReentryError synchronously.
- dispose() marks every live trace aborted with reason 'disposed' so
late ctx.emit() calls (e.g. from compensating cleanup) get a clean
rejection instead of an exception.
Diagnostics gain four new event types
(action.interrupted, event.emitted, reentry.blocked, trace.aborted)
and every existing one carries the envelope identifiers
(runId, eventId, traceId, parentEventId, depth) where applicable, so a
log sink can correlate runs without parsing variant tags.
Tests: 10 new tests covering envelope identity (root depth=0, child
depth+1), ctx.emit() trace inheritance, run-trace correlation, orphan
emit, all four reentry guards (maxDepth with disjoint event names so
the same-name limit doesn't interfere, repeatedEventLimit, error
policy throwing OrcaReentryError, abort-trace, dedupeKey), and the
invariant that bus publishes start fresh traces.
Active-app presets keep working unchanged (they don't call ctx.emit
yet); the API extension is additive on the OrcaActionContext side
(presets still type-check against the wider context shape).
Total: 1357/1357 vitest tests pass (47 in orca, +10 from this commit).
Roadmap v1 documented at the foot of the orca README and parked under
@v1+ in the source: actionTimeoutMs runtime, compensate invocation,
after/unless/abortOn gating, OrcaFatal distinction, queue policies
(commit/replace/parallel), transaction/atomic groups, payload-bearing
tokens, fan-in, validate()/commit() static graph validation,
createActiveOrca() reactive wrapper, and the bus.publish interception
(Option B) that would let modules' direct publishes attach
emittedByAction perfectly.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
1515df1be3 |
Update docs site to reflect post-big-bang App architecture
The /active/* documentation site still taught the pre-2026-05 API
surface — App.createActiveSession(), autoInvalidateOn / autoReauthOn,
APP_EVENT_USER_IDENTITY_CHANGED, App.createSiumEngine(). Refreshed every
page so users see the current model:
- Lowercase services (App.lang, App.cache, App.session, App.perm, …)
instead of the deleted uppercase aliases.
- createActiveApp({ services: { x: defineActive*(...) } }) instead of
createActiveApp({ x: ... }) + App.createActive*().
- applyStandardOrca(App) (or cherry-picked apply* presets) instead of
consumer-side autoInvalidateOn / autoReauthOn flags.
- SESSION_EVENT_IDENTITY_CHANGED on App.Bus instead of the (gone)
APP_EVENT_USER_IDENTITY_CHANGED translator output.
- Single-instance services enforced by the schema's object-literal
semantics, not runtime AlreadyCreatedError throws.
Touched: artifact-docs.ts (the central data source), the long-form
docs/aapp + docs/perm + docs/lang pages, the four get-started pages,
the security page, the root /active page, plus three nav components.
Also fixes a pre-existing bug from an earlier rename: a few imports of
SvelteKit's $app/state, $app/paths, $app/environment had been
incorrectly rewritten to $active-app/* (which doesn't exist as a
SvelteKit alias), leaving the docs site responding 500 to every route.
Restored the correct $app/* imports in:
- active/_components/{Sidebar,PageNav,Toc}.svelte
- active/+page.svelte, test pages (conn, ecosystem, perm, stor, logr,
+page.svelte for /test and /)
- JSDoc example in arts/session/ssr.ts
active/docs/cach/+page.svelte now reads artifactDocs.cache to match
the renamed key in artifact-docs.ts.
Verification: 1347/1347 vitest tests pass, all 11 sampled docs routes
return 200 with zero console/page errors (sampled /active and the
get-started + docs pages for aapp, perm, cach, sess, sium, conn).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
48404bb037 |
Move setBus/getBus to $bus; the bus owns the propagation pattern
The Svelte-context bridge `setBus(bus)` / `getBus()` previously lived in
arts/active-app/bus-context.svelte.ts. That placement was wrong: the
helper does not depend on App, doesn't know about services, and serves
any consumer holding an EngineBus — including isolated test buses or
secondary buses for embedded sub-trees. Its semantic owner is the bus.
Moves:
arts/active-app/bus-context.svelte.ts -> arts/bus/svelte/context.svelte.ts
AappBusNoContextError -> BusNoContextError (libs/bus)
APP_ERR_BUS_NO_CONTEXT (code) -> BUS_ERR_NO_CONTEXT
APP_BUS_CONTEXT_KEY (string constant) -> Symbol inside the helper
`setBus` / `getBus` are re-exported from the `$bus` barrel; no consumer
needs to know the file path. Imports change from `$active-app` to `$bus`:
-import { setBus } from '$active-app';
+import { setBus } from '$bus';
The dropped surface area in arts/active-app:
- bus-context.svelte.ts (file)
- APP_BUS_CONTEXT_KEY (consts)
- APP_ERR_BUS, APP_ERR_BUS_NO_CONTEXT, APP_ERROR_MSG_BUS_NO_CONTEXT (errors)
- AappBusNoContextError class + isAappBusNoContextError guard
- setBus/getBus/AappBusNoContextError/isAappBusNoContextError barrel exports
Verification: 1347/1347 vitest tests still pass; the demo's +layout
imports from $bus and the page renders all 11 cards with sign-in working
and zero console/page errors.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
eb6001fae4 |
Reduce App core to Logger/Bus/Timers/Orca; everything else is opt-in services
Big-bang replacement of the active-app composition: legacy uppercase surface
(App.Lang, App.Cache, App.Format, App.Frontend, App.Dom, App.Storage, App.Http)
removed entirely. All non-core artifacts are now opt-in via services schema:
services: { cache: defineActiveCache(), lang: defineActiveLang(...), ... }
Schema services are exposed as lowercase properties (App.cache, App.lang, …)
with end-to-end type safety; accessing a service the schema didn't declare
is a compile error.
Three import paths split for honest tree-shaking:
$active-app createActiveApp + core types/errors/bus-context
$active-app/services defineActive* / defineEngine* factories
$active-app/presets applyCache* / applyPerm* / applyStandardOrca
Service factories declare core deps (logger/bus/timers/orca) and sibling
service deps (e.g. format wires localeSource from lang automatically when
both are declared). The builder validates names, computes topological order,
detects cycles, builds immediates eagerly, and exposes lazy proxies that
materialise on first access. factory.create() runs inside untrack so
subscriptions wired during construction (e.g. lang.onLocaleChange) cannot
crash the outer reactive scope when triggered from a $derived.
Reactions to lifecycle events (cache.clear on revoke / identity change,
perm.invalidate on identity change) move from internal bus subscriptions
inside arts to opt-in orca presets registered by the application:
applyStandardOrca(App) // or cherry-pick individual apply* functions
Also lands a working showcase at /demo wiring 10 of 12 services
(everything except auth/connections, which need a real server) plus a
mocked perm fetcher and a real http client against jsonplaceholder.
Misc cleanup along the way:
- libs/cache/{key,policy,scope}.ts: missing CACHE_VALIDATION_MESSAGES
imports (the throw paths were never covered by tests, so the bug
only surfaced via the demo)
- All arts READMEs scrubbed of autoInvalidateOn / APP_EVENT_USER_*
references; bus README rewritten around the orca-preset model
- refactorizacion.md moved out of src/ into docs/
Verification: 1347/1347 vitest tests passing, demo loads and exercises
all wired services in a real browser with zero console errors.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
c6de4a11f1 |
Mark refactorizacion.md as completed — big-bang shipped
Closes the working document. Replaces the 'Lo que falta' checklist with the actual list of removals applied in commits |
5 months ago |
|
|
64ab1f0b63 |
Big-bang: remove legacy translators, App.createActiveX(), APP_EVENT_*, autoInvalidate*
Completes step 3 of the active-app refactor. The orca-based service
schema model is now the single supported path; the legacy
auto-reactive ecosystem is gone.
Removed:
- arts/active-app/integrations/session-translator.ts and auth-cache.ts
(their purpose is replaced by orca presets in arts/active-app/presets/).
- arts/connection/bus-session-source.ts (canonical session events
flow through SESSION_EVENT_* directly).
- libs/active-app/ entirely. Its contents (consts, errors, events
reduced to APP_EVENT_DISPOSE_STARTING) consolidated into
arts/active-app/{consts,errors,events}.ts. The libs layer no longer
has anything app-specific.
- From arts/cache:
- bus / autoInvalidateOn options on ActiveCacheOptions.
- wireAutoInvalidation internal subscription.
- CACHE_AUTO_INVALIDATE_* constants and types.
- From arts/perm:
- bus / autoInvalidateOn options on ActivePermsOptions.
- wireAutoInvalidation internal subscription.
- PERM_AUTO_INVALIDATE_* constants and types.
- From arts/connection:
- bus option in EngineConnectionsOptions.
- shouldWireBusSessionSource helper.
- The "reacts to canonical app identity bus events" test that
depended on the deleted bus-session-source.
- From arts/active-app/active-app.svelte.ts:
- createSiumEngine() / createActiveSession() / createActiveConnections() /
createActivePerms() / createActiveAuth() factory methods.
- App.Sess / App.Perms / App.Auth getters and the singleton
guards (Sess !== undefined etc.).
- APP_ORCHESTRATION_* preset system, resolveActiveAppOrchestration,
STANDARD_ORCHESTRATION_TRANSLATORS, all five translator handles.
- APP_ERROR_ALREADY_CREATED_* / APP_ERROR_CREATE_PERM_ENDPOINT_REQUIRED
constants (orphan after factory removal).
- From arts/active-app/test:
- ecosystem.integration.test.ts (9 monolithic tests, ~1900 lines).
- session-translator.test.ts.
- create-sium-engine.test.ts.
- From libs/active-app/test:
- events.test.ts (covered the deleted publishers and the legacy
APP_USER_IDENTITY_* causes).
- APP_EVENT_USER_IDENTITY_CHANGED, APP_EVENT_TENANT_SWITCHED,
APP_EVENT_PERMISSIONS_REFRESH_REQUESTED,
APP_EVENT_CACHE_INVALIDATE_REQUESTED, APP_EVENT_CONNECTIVITY_CHANGED
(only DISPOSE_STARTING survives).
- Their associated payload interfaces and the
APP_USER_IDENTITY_CAUSE_* constants.
- publishAppUserIdentityChanged / publishAppPermsRefreshRequested /
publishAppCacheInvalidateRequested / publishAppTenantSwitched /
publishAppConnectivityChanged. publishAppDisposeStarting and the
new onAppDisposeStarting helper remain.
Final shape of arts/active-app/:
- active-app.svelte.ts: builds Logger, Lang, Format, Frontend, Dom,
Storage, Http, Timers, Bus, Orca, Cache, then the schema services
via buildServiceBuilders. dispose() publishes DISPOSE_STARTING and
tears everything down in reverse construction order.
- services.ts, service-builder.ts, service-factories/, presets/,
bus-context.svelte.ts, consts.ts, errors.ts, events.ts, types.ts,
index.ts (public barrel exposing every define*, applyStandardOrca,
types and errors).
Suite: 1374 tests pass. The reduction from the prior 1408 reflects the
deleted legacy tests; coverage of the new model is comprehensive
(schema-declarative.test.ts, service-builder.test.ts,
service-factories.test.ts, presets.test.ts, active-app.test.ts core,
plus the existing per-art suites).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
01a85ad299 |
Replace legacy ecosystem tests with focused composition tests
Removes the two large legacy integration suites:
- ecosystem.integration.test.ts (9 monolithic tests, ~1900 lines,
14 occurrences of autoInvalidateOn, exercising the
APP_ORCHESTRATION_STANDARD path that is being removed).
- session-translator.test.ts (validates wireSessionTranslator,
which is also being removed).
Replaces active-app.test.ts (1072 lines, 26 tests with heavy
dependence on App.createActiveX() and publishApp* publishers) with
~200 lines of focused composition tests:
- core surface (Logger, Lang, Format, Frontend, Dom, Storage,
Http, Timers, Bus, Orca, Cache, dispose).
- locale flow (setLocale, onLocaleChange).
- mono-lang behavior (path passthrough, warn-once, |fallback).
- dispose idempotency and Orca teardown.
The new model's coverage already lives in:
- schema-declarative.test.ts — declarative App.cache / App.session
end-to-end.
- service-builder.test.ts — topology, lazy proxies, dispose.
- service-factories.test.ts — each defineActiveX wired against a
real core.
- presets.test.ts — orca actions registered via applyStandardOrca
react to SESSION_EVENT_*.
Total suite: 1383 pass (down from 1408 — the deleted legacy tests
were exercising paths that disappear entirely in the big-bang).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
4299c3071d |
Update refactorizacion.md with implementation status and remaining big-bang plan
Captures the state after the long implementation session: steps 1+2 done, step 3 partially done (model active, legacy deprecated), 13 items left for the dedicated big-bang session. The 'Lo que falta' list points to concrete file:line locations and test counts so the next session has a precise checklist. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
60e130b656 |
Mark legacy active-app APIs as @deprecated with migration guidance
Adds @deprecated jsdoc to every API that the orca-based service-schema
model replaces. No runtime change; the legacy paths continue to work
end-to-end, but IDEs and consumers see the strikethrough and the
recommended replacement.
Marked deprecated:
- ActiveCacheOptions.bus / autoInvalidateOn — use the orca preset
applyCacheClearOnIdentityChange (or applyStandardOrca) instead.
- ActivePermsOptions.bus / autoInvalidateOn — use the orca preset
applyPermInvalidateOnIdentityChange.
- App.createSiumEngine / createActiveSession / createActivePerms /
createActiveAuth / createActiveConnections — declare the matching
service in `services: { … }` and access via the lowercase
property (App.session, App.perm, …).
- App.Sess / App.Perms / App.Auth — replaced by App.session /
App.perm / App.auth from the schema.
- ActiveAppOptions.connections / permissions / auth / orchestration
— same migration as above.
- publishAppUserIdentityChanged — subscribe to
SESSION_EVENT_IDENTITY_CHANGED directly (or use the orca preset).
- publishAppPermsRefreshRequested — call App.perm.refresh().
- publishAppCacheInvalidateRequested — call App.cache.clear().
- publishAppConnectivityChanged — slated for arts/connection to
own its CONNECTION_EVENT_*.
- publishAppTenantSwitched — no module owner today; apps emit
their own event.
The big-bang removal of these APIs requires migrating the 9-test
ecosystem suite, the 26 active-app tests and any consumer pages.
That stays scheduled for a session with dedicated time. Until then
this commit communicates the direction without breaking anything.
Tests: 1408 pass (no behavior change).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
7148a5d2ec |
Wire AppServiceSchema into createActiveApp() alongside legacy core
createActiveApp() now accepts an `options.services: TSchema` object
and exposes each declared service as a lowercase property on the
returned App. Schema services coexist with the legacy uppercase
core (App.Cache, App.Bus, App.createActiveSession() etc.) — neither
collides with the other and apps can adopt the schema gradually.
Type changes:
- ActiveApp<S, TSchema = AppServiceSchema> intersects
ActiveAppLegacy<S> (the uppercase core + factory methods),
ResolveServiceInstances<TSchema> (schema instances), and
ActiveAppServicesIntrospection ({ services: { … } status map }).
- ActiveAppOptions<S, TSchema> adds the optional `services?` slot.
Runtime changes:
- createActiveApp builds a CoreServices snapshot (logger, bus,
timers, orca) after Bus + Timers + Orca are constructed.
- When `services` is provided, buildServiceBuilders() is invoked
and every key becomes a getter on the App; reading triggers
lazy construction. Immediate services build during
createActiveApp().
- dispose() runs schema services first (in reverse construction
order) and then the legacy core in its existing order.
- When `services` is absent, App.services returns an empty frozen
object so introspection still works.
Tests:
- active-app.test.ts: API surface includes the new `services` key.
- schema-declarative.test.ts (new, 6 cases): lowercase access,
lazy construction, coexistence with legacy uppercase, dispose,
introspection map, empty schema fallback.
Total suite: 1408 pass (1402 + 6 new). The legacy translators,
APP_EVENT_* publishers and App.createActiveX() factories are still
present; their removal lands in subsequent commits of step 3.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
fb2e3ac507 |
Add App.Orca to the createActiveApp() core
App.Orca is the orchestration engine instance built alongside Logger, Bus and Timers. It is inert until the application registers actions via App.Orca.onEvent() or applies a preset from arts/active-app/presets/. Construction order: Logger → Lang → Storage → ... → Timers → Bus → Orca → Cache → (lazy services). Orca disposes before Bus and Timers to ensure its bus subscriptions and any future timer-based features are torn down cleanly. This is the first surgical change of step 3 (the big-bang merger of the new service-schema model with the legacy createActiveApp). The legacy App.createActiveX() factories remain in place; subsequent commits will migrate the schema-driven services and remove the legacy translators / orchestration translators / APP_EVENT_* patches. Tests: API surface test in active-app.test.ts updated to include the new Orca key. Total suite: 1402 tests pass. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
a04fa67152 |
Add cache/perm/session/connections service factories and orca presets
Closes the second half of step 2 of the active-app refactor: every
service in the schema now has a defineActiveX/defineEngineX factory,
and the orchestration that lived inside arts/cache and arts/perm as
internal bus subscriptions moves to opt-in presets registered via
App.Orca.
Service factories added (4):
- defineActiveCache — passes only logger from core. The legacy
autoInvalidateOn / bus options are still accepted for back-compat
but no longer recommended.
- defineActivePerm — same shape as cache; perm endpoint required
via options.
- defineActiveSession — wires core.bus into the session so
SESSION_EVENT_LIFECYCLE_* events flow without per-app config.
- defineActiveConnections — requires logger + timers from core.
Presets added in arts/active-app/presets/ (4):
- applyCacheClearOnIdentityChange — listens to
SESSION_EVENT_IDENTITY_CHANGED, calls cache.clear().
- applyCacheClearOnRevoke — listens to SESSION_EVENT_REVOKED,
calls cache.clear().
- applyPermInvalidateOnIdentityChange — listens to
SESSION_EVENT_IDENTITY_CHANGED, calls perm.invalidate().
- applyStandardOrca — aggregator that registers every preset whose
services are present on App. Returns a single detacher.
Each preset is a function (App: AppShape) => () => void, where
AppShape is structurally typed against the orca instance and the
specific services the preset needs. Presets cherry-pick what they
need from each service via Pick<…, 'clear' | 'invalidate'>.
Tests: 8 cases for the presets (publish event → assert imperative
API called, detacher unregisters, aggregator skips absent services,
errors recorded in run trace). Total suite: 1402 tests pass
(1394 + 8).
Pending for the big-bang merge in a separate session:
- Rewrite createActiveApp() to consume the schema and remove the
legacy App.createActiveX() factories.
- Delete wireSessionTranslator, createAuthCacheInvalidator and
APP_ORCHESTRATION_*.
- Delete APP_EVENT_USER_IDENTITY_CHANGED / TENANT_SWITCHED /
PERMISSIONS_REFRESH_REQUESTED / CACHE_INVALIDATE_REQUESTED /
CONNECTIVITY_CHANGED. Keep only DISPOSE_STARTING.
- Migrate web/routes/* and the ecosystem integration tests.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
d528652640 |
Add AppServiceSchema contract, builder and pure-art service factories
First half of step 2 of the active-app refactor. Lays the foundation
for the declarative service-schema model documented in
arts/active-app/refactorizacion.md (sections 8.4 and 11). Does NOT yet
rewrite createActiveApp() — that big-bang lands together with the
removal of the legacy translators in step 3.
Pieces added:
- services.ts: AppServiceFactory<TName, TCoreDeps, TServiceDeps,
TInstance>, CoreServices (logger, bus, timers, orca),
AppServiceSchema, ServiceInitMode, ServiceStatus,
ResolveServiceInstances<TSchema>.
- service-builder.ts: validates the schema (key === factory.name),
computes topological order with cycle detection, builds
`immediate` services in order, exposes lazy getter proxies for
`lazy` services, tracks per-service status, disposes in reverse
construction order swallowing dispose errors.
- errors.ts: AppServiceNameMismatchError,
AppServiceDependencyCycleError (carries the cycle path),
AppServiceConstructionFailedError (wraps the original cause).
Codes consolidated into APP_ERROR_MESSAGES via rule 6.
- service-factories/ — pure-art adapters that don't subscribe to
APP_EVENT_*: lang, storage, format, dom, frontend, http, sium,
auth. Each one is a thin wrapper that adapts createActiveX or
createEngineX into the AppServiceFactory shape.
Pending for step 2/3 merger:
- cache, perm, session, connections factories — they still
auto-subscribe internally to APP_EVENT_*; that subscription
lifts out as orca presets in step 3.
- Rewrite createActiveApp() to consume the schema and remove the
legacy `App.createActiveX()` factories.
Tests: 19 unit cases for the builder (schema validation, topology,
init modes, failure handling, disposal) + 4 integration cases that
build a real core (Logger, Bus, Timers, Orca) and instantiate every
factory through the builder. Total suite: 1394 tests pass (1371 + 23).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
0eddd2a0e6 |
Implement arts/orca v0.0 — orchestration engine (surface complete, motor minimal)
First step of the active-app refactor (see arts/active-app/refactorizacion.md).
orca is the orchestration motor that replaces the embryonic
APP_ORCHESTRATION_TRANSLATOR_* system in aapp. Presets registered via
App.Orca.onEvent() will replace the internal bus subscriptions in
arts/cache, arts/perm and arts/connection in step 3.
v0.0 implements the full public contract documented in the appendix E of
the refactorizacion document:
- createEngineOrca({ bus, timers, logger }) — engine factory.
- onEvent(event, action) — registration with detach. Lazy bus
subscription per event; auto-unsubscribes when the last action is
removed.
- Stages (guard/pre/main/post/cleanup/finally) executed in canonical
order; same-stage actions in registration order. FINALLY always
runs, even after abort.
- Result helpers (orcaSuccess, orcaSkipped, orcaError, plus orcaTimeout
and orcaFatal as v0.1+ shapes producible by authors but not by the
engine).
- Run trace: OrcaRunResult with startedAt/endedAt/durationMs and per-
action OrcaActionRun entries with status / emitted tokens.
- Concurrency: implicit QUEUE per event. Events arriving during a run
enqueue FIFO and are processed sequentially.
- Catalogued diagnostics via $libs/logger (RUN_STARTED, RUN_COMPLETED,
RUN_ABORTED, ACTION_STARTED, ACTION_COMPLETED, ACTION_FAILED,
ACTION_SKIPPED, CONFIGURATION_INVALID).
- Error infrastructure follows rule 6: codes + ErrorMessages dict +
classes + guards in arts/orca/errors.ts.
Accepted-but-ignored fields (forward-compat for v0.1+):
- after / unless / abortOn — token coordination ignored.
- actionTimeoutMs — long actions hang.
- compensate — never invoked.
- ABORT_ACTION / ABORT_STAGE — treated as CONTINUE.
Tests: 37 cases covering registration, execution, error policies,
concurrency, run trace, disposal, and forward-compat acceptance of the
@v0.1+ fields. Total suite: 1371 tests pass (1334 + 37).
Adds $orca alias to svelte.config.js. No other module references orca
yet — App.Orca will be wired in step 2 (aapp service-schema refactor).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
f49c60d144 |
Expand active-app refactorizacion.md with orca v0.0 contract
Adds three sections to the working document:
- §8 Architectural review round 1: concrete code proposals for
services.ts, active-app.svelte.ts and types.ts; decisions on the
open questions (Bus always present, big-bang migration, optional
TSchema with default {}); list of legacy code that disappears with
the refactor.
- §9 Architectural review round 2: orca v0.0 as a hard pre-requisite
for the aapp refactor (surface complete, engine minimal). Critical
correction over §3 — presets and define*() factories live in
arts/active-app/ (presets/ and service-factories/), not in each
art, so arts stay pure and the dependency inversion is preserved.
App.Orca chosen as the namespace label.
- §10-§11 Revised 4-step implementation plan and consolidated 17-item
decision list.
- Appendix D: final directory layout plus pure-art / factory / preset
examples.
- Appendix E: full EngineOrca v0.0 contract including consts.ts,
errors.ts, types.ts (with @v0.0 / @v0.1+ markers on every accepted-
but-ignored field), result.ts helpers, engine-orca.ts implementation
(~600 lines), index.ts barrel, test matrix and explicit list of what
the v0.0 engine does NOT do.
No code in src/* changed. Implementation pending.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
857fcd1049 |
Add refactorizacion.md documenting active-app redesign plan
Working document capturing the architectural analysis for arts/active-app: removal of APP_EVENT_* patches, decoupling cache/perm/connection from App-level events, and migration to a declarative AppServiceSchema with core (always present) vs services (opt-in) distinction. Lays out the phased plan for execution and the contract that orca v0 expects. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
3afcf00900 |
Move runtime types and SILENT_* implementations from libs/* to arts/*
Pure libs/* keeps only abstract contracts (TimerScheduler, EventPublisher, EventSubscriber, BusEnvelope, LangNode, plus codes and ERROR_MESSAGES dicts). Runtime interfaces (Engine*, Active*, Engine*Options) and concrete no-op implementations (SILENT_BUS, SILENT_LOGGER) move to arts/*. Cross-layer moves: - EngineLang, ActiveLang: libs/lang/types.ts → arts/lang/types.ts - EngineBus, EngineBusOptions: libs/bus/types.ts → arts/bus/types.ts - SILENT_BUS: libs/bus/silent-bus.ts → arts/bus/silent-bus.ts - SILENT_LOGGER: libs/logger/silent-logger.ts → arts/logger/silent-logger.ts - EngineTimers, EngineTimersOptions: libs/timer/types.ts → arts/timer/types.ts - bus-context.svelte.ts: libs/active-app/ → arts/active-app/ New: EventSubscriber<TEvents> contract in libs/bus/types.ts. EngineBus now extends EventPublisher + EventSubscriber. libs/active-app/events.ts uses it for AppEventBus instead of Pick<EngineBus, 'on' | 'once'> so the libs layer no longer references the runtime interface. libs/logger/diagnostics.ts uses a private NOOP_LOGGER fallback. The public SILENT_LOGGER exports from $logger. Apply rule 6 to arts/timer: ErrorMessages dict (libs/timer/errors.ts) now references the same canonical builders the Timer*Error classes use, so the message lives in one place. Class constructors take semantic parameters (method, key, delayMs) instead of pre-formatted strings. Apply rule 6 to libs/days: codes + ErrorMessages + classes + guards. arts/format/errors.ts removed (FORMAT_ERROR_MESSAGES.INVALID_LOCALE was dead code). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
369ba66097 |
Move error message constants from consts.ts to errors.ts
Each module's `_ERROR_MSG_*` strings and the helper functions that build
error messages now live in `errors.ts` alongside the codes, classes and
guards. `consts.ts` keeps only non-error values: log messages, method
names, event types, configuration defaults.
Modules updated: arts/{auth,cache,connection,http,perm,session,timer},
libs/perm, svrs/{cache,perm}. The libs/errs exception (codes inline in
consts.ts due to import cycle with the foundational error system) is
preserved.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
0b2c4eb30b |
Consolidate error infrastructure into errors.ts per module
Apply the canonical error pattern (docs/conventions.md rule 6) to the remaining 16 modules: every module's <MOD>_ERR seed, <MOD>_ERR_* codes, <MOD>_ERROR_MESSAGES catalogue, error classes and is*Error guards now live in a single errors.ts file. consts.ts retains only configuration unrelated to errors (event names, default values, op identifiers). Modules consolidated: - libs/active-app, libs/auth, libs/bus, libs/cache, libs/dom, libs/lang, libs/perm, libs/timer (new errors.ts) - arts/active-app, arts/auth, arts/connection, arts/http, arts/logger, arts/perm, arts/session, arts/sium - svrs/perm `<MOD>_ERROR_MESSAGES: ErrorMessages` declared in every module, indexed by ErrCode. The ErrorMessages type was added to libs/errs/code in the previous pass; this commit propagates its use everywhere. `libs/errs/consts.ts` is the documented exception: its codes (`errs::format_invalid`, `errs::unknown`) live as string literals in consts.ts because errors.ts imports them and code.ts imports CodeFormatError from errors.ts — the import graph forbids using errCode() at that position. Side cleanups: - libs/cache: legacy CACHE_ERROR_MESSAGES dict (validation strings) renamed to CACHE_VALIDATION_MESSAGES so the canonical CACHE_ERROR_MESSAGES (ErrorMessages indexed by ErrCode) is the only symbol with that name. - libs/perm: PERM_MODULE = 'perm' added (it was implicit before). - arts/auth, arts/perm, arts/active-app: client-only error codes (request_failed, disposed, invalid_response, no_context, etc.) live in the artifact's errors.ts but reuse the libs <MOD>_ERR seed so every code in the family shares the same module prefix. - libs/timer: errors.ts created (didn't exist) housing the codes that were previously in consts.ts; library has no classes (timer error classes live in arts/timer/errors.ts and import the codes from libs/timer). - arts/sium: SIUM_ERR seed, codes and three error classes (SiumValidationError, SiumAsyncSchemaError, SiumDiscriminatedUnionError) consolidated. Classes were previously in core/types.ts; that file no longer carries error infrastructure. All call sites in arts/sium/core/* and arts/sium/types/* updated their imports from `./types`/`../core/types` to the module's `errors.ts`. All 1334 tests pass. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
7f2577c8da |
Rename permissions→perm, formats→format; consolidate sium error infra
Two more module renames flipping the direction of the previous pass: - arts/permissions, libs/permissions, svrs/permissions, libs/svrs/permissions.ts → arts/perm, libs/perm, svrs/perm, libs/svrs/perm.ts. Alias: $permissions → $perm. Constants: PERMISSION_* → PERM_*. Wire: 'permissions::*' → 'perm::*'. Module value: 'perm'. Class names: Permission*Error → Perm*Error. Helper functions: permissionDecisionKey → permDecisionKey (and similar). - arts/formats → arts/format (with the four sub-modules currency, numbers, units, dates carried along). Alias: $formats → $format. Constants: FORMATS_* → FORMAT_*. Wire: 'formats::*' → 'format::*'. Class names: Formats*Error → Format*Error. Both follow the auth/http/dom precedent: short word as the canonical name. The earlier full-word forms (permissions, formats) created asymmetric prefixes (PERMISSION_* singular, PERMISSIONS_REFRESH plural) that were already showing as drift in this commit's call sites. Plus a fix to sium error structure that was carried over from the previous audit round but never fully consolidated: - arts/sium/errors.ts now owns the full error infra: SIUM_ERR seed, all SIUM_ERR_* codes, SIUM_ERROR_MESSAGES catalog, error classes (SiumValidationError, SiumAsyncSchemaError, SiumDiscriminatedUnionError), guards and the SIUM_ERROR_MESSAGES type. The legacy SIUM_ERRORS string catalog stays for the few non-thrown sites until those are migrated. - arts/sium/consts.ts no longer carries error codes — only module identifier and diagnostic events. - arts/sium/core/types.ts no longer carries error classes — only schema types. - All call sites in arts/sium/core/* and arts/sium/types/* now import the error classes from `../errors` instead of `../core/types` / `../consts`. This is the canonical pattern documented in conventions.md rule 6: all of a module's error infrastructure lives in a single errors.ts file; consts.ts is for module configuration that has nothing to do with errors. Sium is now compliant; the rest of the modules will follow in subsequent commits. All 1334 tests pass. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
4db6bd2b3b |
Rename modules from 4-letter aliases to full English words
Drops the 4-letter alias convention in favour of a single homogeneous
naming axis: full English words across filesystem, alias, wire format
and constants.
Module renames:
- arts/aapp → arts/active-app (libs/aapp also)
- arts/buss → arts/bus (libs/buss also)
- arts/cach → arts/cache (libs/cach + svrs/cach also)
- arts/conn → arts/connection
- arts/fend → arts/frontend
- arts/fmts → arts/formats (curr→currency, nums→numbers, unts→units)
- arts/logr → arts/logger (libs/logr also)
- arts/perm → arts/permissions (libs/perm + svrs/perm also)
- arts/sess → arts/session
- arts/stor → arts/storage
- arts/timr → arts/timer (libs/timers → libs/timer)
Modules left as-is: auth, dom, errs, http, lang, sium (already match
their canonical name or are proper names).
Special case: `aapp` could not become `app` because `$app` is reserved
by SvelteKit (`$app/stores`, `$app/navigation`, ...). Compromise:
- Filesystem and alias use `active-app` / `$active-app`.
- Constants and class names use `App` / `APP_*` (no `active-` prefix).
The `active-` prefix only disambiguates the alias from SvelteKit's
namespace; the module is App.
Special case: `permissions` keeps the plural for filesystem/alias/wire
but constants and classes use the singular `PERMISSION_*` /
`Permission*` because they describe the concept ("a permission
effect"), not the module collection.
Constants follow the new module name in caps: `STORAGE_*`, `BUS_*`,
`CACHE_*`, `CONNECTION_*`, `FORMATS_*`, `LOGGER_*`, `SESSION_*`,
`TIMER_*`, etc. Module values: `STORAGE_MODULE = 'storage'`,
`BUS_MODULE = 'bus'`, `APP_MODULE = 'app'`,
`PERMISSION_MODULE = 'permissions'`, etc.
Wire/code format moved accordingly: `'storage::*'`, `'bus::*'`,
`'session::*'`, `'permissions::*'`, etc. Diagnostic event values
updated: `'storage.error'`, `'bus.event.published'`,
`'connection.auth_failed'`, etc. App events use `'app.*'`:
`AAPP_EVENT_* → APP_EVENT_*` with values `'app.user.identity.changed'`.
Class renames (where they used the abbreviation):
- AappAlreadyCreatedError → AppAlreadyCreatedError
- BussError* → BusError* (where applicable)
- Cach* → Cache*
- Conn* → Connection* (e.g. ConnDisposedError → ConnectionDisposedError;
ConnConnection* collapsed to Connection*)
- Logr*Error → Logger*Error
- Sess* → Session* (SessInvalidSessionError → SessionInvalidError)
- Stor* → Storage*
- Timr* → Timer* (TimrInactiveTimerError → TimerInactiveError)
- AuthCachPort → AuthCachePort
- AuthClientCach* → AuthClientCache*
- AuthPermPort → AuthPermissionsPort
Property renames in option types:
- `cach?:` → `cache?:` in AuthClient options
- `logr:` → `logger:` in svrs/auth ports
- `timr:` → `timer:` in svrs/auth ports
`docs/conventions.md` rewritten:
- Rule 1 dropped the 4-letter alias mandate; lists the full English
module names and special-cases active-app, lang, sium, permissions.
- Rule 2 documents the new constant prefix convention and its two
exceptions (APP_* for active-app, PERMISSION_* singular for
permissions).
- Rule 6 codifies that all error infrastructure (codes, messages,
classes, guards) lives in a single `errors.ts` per module —
removing the `consts.ts` / `errors.ts` split for error-related
symbols.
`libs/errs` adds `ErrorMessages` type so every module can declare its
catalog as `<MOD>_ERROR_MESSAGES: ErrorMessages` instead of repeating
the `Readonly<Record<ErrCode, string | (...args) => string>>` shape.
Storage migrated as the first proof of the canonical pattern.
All 1334 tests pass.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
dace6d00d1 |
Add libs/errs README documenting the canonical error system
Captures the conventions that landed across the audit-1-5 migration: ErrCode and ModuleSeed shapes, the `errCode(parent, segment)` builder, the per-module recipe (consts.ts + errors.ts + guards), family matching with `matches(err, family)`, i18n derivation via `codeToLangPath()`, the immutable decorator API, wire-safe projections, and the don'ts (no string-concat construction, no parallel `<MOD>_ERROR_CODES` legacy enums, no `instanceof Error`). Closes the last open item from the errs migration. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
97d8b605b9 |
Consolidate libs/auth errors onto CodeError (option B)
The auth artifact had its own parallel error system: AUTH_ERROR_CODES
(strings like `'AUTH_CONFIG_INVALID'`), AUTH_SAFE_MESSAGES
(`'auth.error.config_invalid'` i18n keys) and `AuthError` extending
`Error` with extra `messageKey`/`code`/`data` fields. With this commit
auth uses the same canonical error system as the rest of the codebase.
What changed:
- libs/auth/consts.ts: AUTH_ERROR_CODES and AUTH_SAFE_MESSAGES gone.
Adds AUTH_ERR seed plus 20 codes (`auth::config_invalid`,
`auth::adapter_failed`, …, `auth::webauthn_failed`).
- libs/auth/errors.ts: AuthError now extends CodeError; the 20
subclasses pass their ErrCode to the base via a thin
`(cause?, data?)` constructor. Type guards unchanged.
- libs/auth/types.ts: AuthErrorCode is now an `ErrCode` alias.
AuthClientSafeError reduces to `{ code: ErrCode }` — the UI derives
the i18n path on demand via `codeToLangPath(error.code)`.
- arts/auth/consts.ts: re-exports AUTH_ERR + the 20 libs codes;
keeps three client-only codes (`request_failed`, `disposed`,
`invalid_response`).
- svrs/auth/handler-runtime.ts: switch statements updated to the new
AUTH_ERR_* identifiers; route-not-found payload is `{ code }` only.
- arts/auth/active-auth-runtime.ts, arts/auth/client.ts: dropped
messageKey from AuthClientSafeError reads/writes.
- Tests in arts/auth + svrs/auth: switched to AUTH_ERR_* constants.
- READMEs (arts/auth, libs/auth, svrs/auth) refreshed: examples now
use codeToLangPath() to derive i18n keys; old AUTH_ERROR_CODES /
AUTH_SAFE_MESSAGES references replaced.
Breaking change: any consumer reading `error.messageKey` must call
`codeToLangPath(error.code)` instead. The wire shape sent to the
client now carries only `{ code }`.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
c2197f58d8 |
Replace remaining generic Error throws with typed CodeError classes
Eight `throw new Error(...)` sites across stor, logr, dom and sium-union now throw typed errors backed by `CodeError` and discoverable via `is*Error` guards: - arts/stor/entry-values.ts → StorValidationFailedError (`stor::validation_failed`) - arts/stor/adapters/cookie.ts → StorCookieServerRequiredError (`stor::cookie_server_required`) - arts/logr/transports.ts → LogrHttpTransportPushFailedError (`logr::http_transport_push_failed`) - arts/logr/adapters/loki.ts → LogrLokiPushFailedError (`logr::loki_push_failed`) - libs/dom/core.ts → DomDocumentRequiredError / DomWindowRequiredError (`dom::document_required`, `dom::window_required`) - arts/sium/core/union-combinators.ts → SiumDiscriminatedUnionError with three sub-codes (`sium::discriminated_union.member_not_object`, `…member_missing_key`, `…member_not_literal`) Adds `LOGR_MODULE`, `LOGR_ERR`, `STOR_ERR`, `DOM_MODULE`, `DOM_ERR` and the new error files / barrel exports. The string catalogs (LOGR_ERRORS, STOR_ERRORS, DOM_ERRORS) stay as message providers; the new classes wrap them. Runtime code now has zero `throw new Error(...)` sites outside vendored day-picker code (libs/days/_vendor) and tests. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
f98fad7e35 |
Migrate arts/http error tree to CodeError
The four engine errors (HttpNetworkError, HttpTimeoutError, HttpAbortError, HttpBodyValidationError) now extend CodeError directly. The intermediate `HttpEngineError` abstract base is gone — CodeError provides the shared shape, and the cause-bearing constructor is no longer needed at a separate layer. Adds HTTP_ERR seed plus four codes (`http::network`, `http::timeout`, `http::abort`, `http::body_validation`); the legacy `HTTP_ERROR_NAME_*` constants are removed. Type guards still compare on `name` (rather than `instanceof`) so they remain stable across worker boundaries; `CodeError` sets `name` from the code, so the cross-realm contract is preserved with a comment that explains why. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
834775099e |
Migrate libs/aapp, arts/aapp and arts/auth errors to CodeError
Three small error catalogs converted to the canonical CodeError + ErrCode system: - libs/aapp: AappBusNoContextError, AappInvalidEventRuntimeError, AappUnsafeEventPayloadError. Adds AAPP_ERR seed plus the bus/event hierarchy (`aapp::bus.no_context`, `aapp::event.invalid_runtime`, `aapp::event.unsafe_payload`). - arts/aapp: AappAlreadyCreatedError. Reuses libs/aapp's AAPP_ERR seed and adds AAPP_ERR_ALREADY_CREATED. - arts/auth: AuthRequestFailedError, AuthDisposedError, AuthInvalidResponseError. Defines AUTH_ERR seed locally; once libs/auth migrates the seed converges (same module name, same `'auth::'` prefix, no conflict). The legacy `AAPP_*_ERROR_NAME_*` and `AUTH_ERROR_NAME_*` constants are removed — the error name now derives from the code, matching the pattern in buss/conn/sess/perm/cach/sium/lang/timr. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
22058e4370 |
Consolidate repeated where-clause casts in db auth adapter
Closes audit-1-5 section 4: six call sites in svrs/auth/adapters/db.ts repeated the same `as unknown as Readonly<Record<string, unknown>>` double cast when forwarding typed inputs to the generic `AuthRepository.findOne` / `findMany` signature. Centralized the cast in a single private `whereOf<T>(input)` helper so future tightening (e.g. adding a brand or replacing the repository where-clause shape) only changes one line. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
a791c2fd53 |
Refresh buss README to match current sess and aapp shapes
Closes audit-1-5 section 5 drift in arts/buss/README.md: - Sess publisher example now uses `publishSessLifecycleEvent` (the fanout publisher) and `onSessChanged`; the obsolete `publishSessIdentityChanged` / `onSessIdentityChanged` example is removed. - Session-translator example uses `resolveAppIdentityCause(payload.event)` to map each lifecycle event to its corresponding cause, instead of hardcoding `APP_USER_IDENTITY_CAUSE_SESSION_ADOPTED` for every event. - App-event constants and string values updated to the real `AAPP_*` prefix: `APP_EVENT_*` -> `AAPP_EVENT_*`, `'app.*'` -> `'aapp.*'`. - `AAPP_EVENT_RUNTIMES` example aligned with the actual shape (uses the `AAPP_EVENT_RUNTIME_BOTH/CLIENT` constants and proper type alias instead of bare string literals). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
28e29b3267 |
Harden dispose idempotency and replace generic throws with typed errors
Closes audit-1-5 section 3.3 and 3.5: - arts/conn and arts/fend `dispose()` now guard against double-call. - arts/lang circular-reference path throws `LangCircularReferenceError` (new typed error in libs/lang) instead of plain `Error`. - libs/perm filter-without-actor path throws the existing `PermissionRuntimeError` instead of plain `Error`. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
742c0118b8 |
Migrate buss/conn/sess/perm/cach errors to CodeError
Continues phase 4 — sweeps the next batch of modules onto the canonical CodeError base. Same mechanical pattern as sium: - Add `<MOD>_ERR` module seed and `<MOD>_ERR_*` codes via `moduleSeed` + `errCode`. - Convert error classes to `extends CodeError`. Drop the hardcoded `this.name = 'XxxError'` literals — `name` derives from the code. - Drop the `<MOD>_ERROR_NAME_*` constants that only existed to feed those literals. - Type guards keep using `instanceof Class` (works through the CodeError prototype chain). - Subclass-specific fields (envelope, failures, depth, type, key, channel, connection, decision, invariant, etc.) preserved. Modules migrated this commit: - libs/buss (4 classes): BusDisposedError, BusAggregateListenerError, BusReentrancyLimitError, BusInvalidPayloadError - arts/timr (5 classes): TimrDisposedError, TimrInvalidKeyError, TimrDuplicateKeyError, TimrInvalidDelayError, TimrInactiveTimerError (codes live in libs/timers; classes stay in arts/timr) - arts/conn (8 classes): ConnDisposedError, ConnConnectionAlreadyExistsError, ConnConnectionNotFoundError, ConnInvalidConnectionNameError, ConnInvalidFrameError, ConnChannelAlreadyExistsError, ConnChannelNotFoundError, ConnWebSocketUnavailableError. Adds the two missing guards flagged by audit-1-5 section 3.2 (isConnChannelAlreadyExistsError, isConnChannelNotFoundError). - arts/sess (3 classes): SessDisposedError, SessAlreadyCreatedError, SessInvalidSessionError. Sess test updated to assert against the new code-based name. - libs/perm + arts/perm + svrs/perm (3+4+2 classes): PermissionDeniedError, PermissionSchemaError, PermissionRuntimeError, PermInvalidEndpointError, PermNoContextError, PermRemoteRequestError, PermDisposedError (×2), PermInvalidBodyError. Codes live in libs/perm; arts and svrs reach into them. - libs/cach + arts/cach + svrs/cach (3+1+1 classes): CacheKeyError, CacheScopeError, CachePolicyError, CachActiveEntryDisposedError, CachDisposedError. Codes consolidated in libs/cach. Plus audit-1-5 section 3.2 cleanup outside the migration: - libs/auth/errors.ts: adds the 10 missing type guards (isAuthAccountNotLinkedError, isAuthSessionRevokedError, isAuthAssuranceRequiredError, isAuthRateLimitedError, isAuthTenantBoundaryError, isAuthOAuthStateInvalidError, isAuthOAuthProviderError, isAuthOtpInvalidError, isAuthMfaRequiredError, isAuthWebAuthnError). Auth's own `code`/`messageKey` shape is preserved for now — full migration to CodeError needs more thought because of the existing AUTH_ERROR_CODES/AUTH_SAFE_MESSAGES dual structure. Verification: svelte-check 1403 files / 0 errors. Server 1315 tests, client 19 tests — all green. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
a849d00bff |
Migrate sium to CodeError + add ModuleSeed/errCode builders
Pilot of phase 4 plus a libs/errs API change introduced after the
user pointed out that `code('buss::disposed')` repeats the module
name redundantly across every declaration.
libs/errs additions:
- New `ModuleSeed` branded type — string of the form `'<module>::'`
produced once per module.
- `moduleSeed(module)` factory: validates the module name and returns
a `ModuleSeed`.
- `errCode(parent, segment)` builder: composes a child `ErrCode` from
a `ModuleSeed` (uses `::` separator) or another `ErrCode` (uses `.`
separator). The builder picks the right separator automatically.
- `isModuleSeed(value)` discriminator.
- `matches(err, family)` now accepts `ModuleSeed | ErrCode`. Passing
a seed matches any error from that module; passing a code matches
hierarchically within the same module. Replaces the
`matchesModule(err, 'buss')` helper introduced earlier in this
session — that helper was redundant once seeds entered the API.
Sium pilot:
- arts/sium/consts.ts: declares `SIUM_ERR = moduleSeed('sium')` plus
the two child codes via `errCode(SIUM_ERR, 'validation')` and
`errCode(SIUM_ERR, 'async_schema')`. Module name appears exactly
once.
- arts/sium/core/types.ts: `SiumValidationError` and
`SiumAsyncSchemaError` extend `CodeError`. Hardcoded
`this.name = 'SiumValidationError'` literals removed. Subclass-
specific fields (`issues`, `schemaKind`) preserved.
- Adds `isSiumValidationError` / `isSiumAsyncSchemaError` guards
(closes audit-1-5 section 3.2 for sium).
- 12 tests in arts/sium/test/errors.test.ts cover subclass shape,
identity, `matches` against seed and exact code, and the fluent
decorator chain.
docs/conventions.md updated:
- Section 4 rewritten around the `moduleSeed`/`errCode` pattern.
- "Family root" wording removed (was misleading — `BUSS_ERR='buss::base'`
was a sibling, not an ancestor of its module's codes).
- `matches` documented as accepting either a seed or an ErrCode.
Verification: svelte-check 1403 files / 0 errors. Server 1315 tests
(+10 from previous), client 19 tests — all green.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
38160565b2 |
Add libs/errs: ErrCode + CodeError canonical error system
Phase 3 of the convention pass — introduces the framework's single canonical error system, designed in dialogue with the user and documented in docs/conventions.md section 4. Public API: - `ErrCode` — branded string type for `module::path.with.dots` identifiers. Validated at construction via `code(value)` (throws `CodeFormatError`) or `isValidCode(value)` predicate. - Helpers: `moduleOf`, `leaf`, `parent`, `sub`, `parts`, `isDescendantOf`, `isEqualOrDescendantOf`, `codeToLangPath`. - `CodeError` — single error class for the framework. Carries a required `ErrCode` (its identity), optional dev-facing `message`, optional `cause`, and a frozen `meta` bag of contextual fields. - Fluent immutable decorators: `withMessage`, `withTime`, `withRequestId`, `withTenant`, `withUser`, `withData`, generic `with(meta)`. Each returns a new `CodeError` with the same code — identity is invariant under decoration. - `isCodeError(value)` type guard. - `matches(value, family)` family-membership predicate, the natural way to catch `if (matches(err, BUSS_ERR))` for everything in the bus. - `CodeFormatError` — bootstrap exception (does NOT extend CodeError to break the circular construction dependency). Format properties: - `module::path.with.dots` — `::` separates module from hierarchy, `.` separates segments inside the path, `_` allowed inside a single segment as a word separator. - Lowercase alphanumeric only. No uppercase, hyphens, slashes, spaces. - Strict descendancy check respects segment boundaries: `'buss::listener_extra'` is NOT a descendant of `'buss::listener'`. - `codeToLangPath` swaps `::` for `.` so the same `ErrCode` can also serve as the i18n path: `t(codeToLangPath(err.code))`. Validation reasons exported as stable string constants (`ERRS_VALIDATION_REASON_*`) so callers can branch on them programmatically without pattern-matching error messages. Tests: 62 in `code.test.ts` + 25 in `code-error.test.ts`. Cover validation paths, all helpers, the fluent decorator chain, immutability, toJSON shape, isCodeError discrimination across CodeError subclasses, and matches() for identity / family / decoration cases. This commit only adds `libs/errs/` — no existing module migrates yet. Phase 4 pilots the new system in `arts/sium`. Verification: svelte-check 1402 files / 0 errors. Server 1292 tests (+62), client 19 tests — all green. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
6b5533c840 |
Add module prefix to all remaining ad-hoc constants
Phase 2B.3 of the convention pass — closes the gap between rule 2
(`<MOD>_<CATEGORY>_<NAME>`) and the codebase. Adds the module's
4-letter alias to constants that previously had none or used a
non-canonical category prefix. ~190 constants renamed across 7
modules.
Bulk renames per module (sed with `\b...\b` word boundaries):
- arts/timr — ENGINE_METHOD_*, LOG_MSG_*, ERROR_PREFIX,
ERROR_NAME_*, ERROR_MSG_* now carry TIMR_ prefix
- arts/conn — TRANSPORT_KIND_*, FRAME_KEY_*, DEFAULT_*,
TIMR_KEY_*, BROWSER_EVENT_*, DOCUMENT_*,
WEBSOCKET_*, MOCK_TRANSPORT_*, LOG_MSG_*,
ERROR_*, FRAME_TYPE_*, METHOD_*, CLOSE_REASON_*
etc. now carry CONN_ prefix
- arts/sess — DEFAULT_*, AUTO_REFRESH_TIMER_KEY,
BROWSER_EVENT_*, DOCUMENT_*, BROADCAST_TYPE,
IDENTITY_*, REVOKE_SCOPE_*, REFRESH_STATUS_*,
ADOPT_REASON_*, SKIP_REASON_*, REVOKE_REASON_*,
INVARIANT_*, ACTOR_*, FIELD_*, ENGINE_METHOD_*,
ERROR_PREFIX/NAME/MSG, LOG_MSG_*, EVENT_* (the
lifecycle ones — see disambiguation below) now
carry SESS_ prefix
- arts/stor — ENTRY_CHANGE_SOURCE_*, DEFAULT_*, BROWSER_EVENT_*,
ENVELOPE_KEY/ERROR_*, NAMESPACE_SEPARATOR now
carry STOR_ prefix
- arts/http — DEFAULT_RETRY*, RETRY_AFTER_HEADERS,
DEFAULT_TIMEOUT, MAX_ERROR_BODY_BYTES, LOG_MSG_*,
ERROR_*, TIMEOUT_SCOPE_*, RESULT_KIND_* now
carry HTTP_ prefix
- arts/fmts — DEFAULT_LOCALE, AUTO_VALUE → FMTS_DEFAULT_LOCALE,
FMTS_AUTO_VALUE
- libs/timers — DEFAULT_BACKOFF_* → TIMR_DEFAULT_BACKOFF_*
- libs/lang — 4 unprefixed → LANG_ prefix
- libs/cach — 1 unprefixed → CACH_ prefix
Lifecycle vs bus event disambiguation (sess):
`arts/sess` had two distinct constant sets that collided after the
prefix add: `EVENT_*` (lifecycle, value `'sess.lifecycle.X'`) and
`SESS_EVENT_*` (bus, value `'sess.X'`). Both ended up with the same
SESS_EVENT_* name. To preserve the distinction:
- Lifecycle declarations renamed to SESS_EVENT_LIFECYCLE_* (matching
the path component already in their values).
- Bus declarations stay as SESS_EVENT_*.
- Consumers split correctly: code that switches on `change.event`
uses LIFECYCLE_ variants; code that publishes/subscribes to bus
uses bus variants.
Conn-side lifecycle redeclarations (`SESS_EVENT_REFRESHED` etc. with
`'sess.lifecycle.X'` values inside arts/conn/consts.ts) became
CONN_SESS_EVENT_* — these are conn-local copies; future cleanup
should import from sess instead of redeclaring.
Verification: svelte-check 1395 / 0 errors. Server 1230 tests, client
19 tests — all green.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
838d000f63 |
Rename APP_* constants to AAPP_* and align event values to aapp.*
Phase 2B.2 of the convention pass. Closes the inconsistency where arts/aapp used APP_* prefix while libs/aapp already used AAPP_*. After this commit every constant under arts/aapp and libs/aapp uses the canonical 4-letter alias `AAPP_` (rule 1 of docs/conventions.md). Constants renamed (~24 total): - APP_EVENT_* → AAPP_EVENT_* (the 6 public events) - APP_USER_IDENTITY_CAUSE_* → AAPP_USER_IDENTITY_CAUSE_* - APP_ORCHESTRATION_* → AAPP_ORCHESTRATION_* - APP_ERROR_* → AAPP_ERROR_* - APP_LOG_MSG_* → AAPP_LOG_MSG_* - APP_CONNECTION_CLOSE_REASON_* → AAPP_CONNECTION_CLOSE_REASON_* - APP_EVENT_RUNTIMES → AAPP_EVENT_RUNTIMES Wire-format change for the public app event values: - 'app.user.identity.changed' → 'aapp.user.identity.changed' - 'app.tenant.switched' → 'aapp.tenant.switched' - 'app.permissions.refresh.requested'→ 'aapp.permissions.refresh.requested' - 'app.connectivity.changed' → 'aapp.connectivity.changed' - 'app.cache.invalidate.requested' → 'aapp.cache.invalidate.requested' - 'app.dispose.starting' → 'aapp.dispose.starting' Per docs/conventions.md rule 5, every event-identifier string value must start with the module's 4-letter alias. Now that AAPP_MODULE = 'aapp' (set in phase 2B.1) is the canonical module identifier, the event scope follows. External observers of these events must update string filters from `app.*` to `aapp.*`. The framework has not been tagged 0.1 yet so the wire format is still in flight. Translation keys (`'app.title'`, `'app.cart'`, `'app.boot'`, etc. used by `App.Lang.t(...)` in the demo / ecosystem test pages) are NOT events and were intentionally left untouched — they're paths in the lang schema, independent of the AAPP module identity. Verification: svelte-check 1395 / 0 errors. Server 1230 tests, client 19 tests — all green. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
a01ef0f63d |
Replace LOGGER_CATEGORY with <MOD>_MODULE single source of truth
Phase 2B.1 of the convention pass. Establishes one canonical constant
per module — `<MOD>_MODULE = '<alias>'` — as the single source for the
module's identifier across logger category, error message prefixes,
event scopes, and any other place the module's name is needed.
What changed:
1. Renamed all `<MOD>_LOG_CATEGORY` constants to `<MOD>_MODULE` (the
value semantics didn't change; only the name). Affected modules:
buss, conn, sess, perm (libs+arts+svrs), timr, lang, auth, http,
sium, cach, stor, aapp (libs+arts), and the four fmts sub-modules
(fmts, fmts.curr, fmts.dates, fmts.nums, fmts.unts).
2. Aligned values with the 4-letter alias where they didn't already:
- STOR_MODULE: 'storage' → 'stor'
- FMTS_MODULE: 'formats' → 'fmts'
- FMTS_CURR_MODULE: 'formats.currency' → 'fmts.curr'
- FMTS_DATES_MODULE: 'formats.dates' → 'fmts.dates'
- FMTS_NUMS_MODULE: 'formats.numbers' → 'fmts.nums'
- FMTS_UNTS_MODULE: 'formats.units' → 'fmts.unts'
3. Unified the duplicate `AAPP_MODULE` declaration: arts/aapp/consts.ts
now re-exports from libs/aapp/consts.ts (canonical source). Both
files used to declare it independently with different values
('app' vs 'aapp').
4. Replaced hardcoded `'[<alias>] ...'` literals in error messages
with template strings using `<MOD>_MODULE`. Every error-message
constant now derives the prefix from the module identifier instead
of hardcoding it. Affected files: libs/aapp/consts.ts, arts/aapp/consts.ts,
libs/buss/consts.ts, libs/lang/errors.ts, arts/stor/errors.ts,
arts/sium/errors.ts, arts/fmts/errors.ts, and the ERROR_PREFIX
constants in arts/conn, arts/sess, arts/http, arts/timr.
5. Updated diagnostic event values to use the new module aliases:
- STOR_DIAGNOSTIC_EVENTS.ERROR: 'storage.error' → 'stor.error'
- All FMTS_*_DIAGNOSTIC_EVENTS values to use 'fmts.X.*'
6. Updated tests that asserted against the old values (storage-integration.test
and fmts/curr/test/barrel.test).
7. Updated docs/conventions.md: replaced the LOG_CATEGORY category
with the new MODULE category. Added the rule that ERROR_MSG values
must use the template `[${<MOD>_MODULE}]`, never a hardcoded literal.
Verification: svelte-check 1395 / 0 errors. Server 1230 tests, client
19 tests — all green.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
14fa92d38c |
Rename constant module prefixes to 4-letter aliases
Phase 2 of the convention pass documented in docs/conventions.md. Aligns every module-level constant's prefix with the bundler alias that already identifies the artifact (rule 1 of the convention): - BUS_* → BUSS_* (libs/buss + arts/buss) - CONNECTION_* → CONN_* (arts/conn + web consumers) - SESSION_* → SESS_* (arts/sess + libs/aapp + consumers) - PERMISSION_* → PERM_* (arts/perm, libs/perm, svrs/perm) - TIMER_* → TIMR_* (arts/timr + libs/timers) - CACHE_* → CACH_* (arts/cach + libs/cach + svrs/cach) - STORAGE_* → STOR_* (arts/stor + consumers) Mechanical sed pass with `\b<OLD>_` word-boundary anchor — this only matches at identifier start, never inside (e.g. AAPP_BUS_CONTEXT_KEY stays untouched because the boundary requirement is between non-word and word characters). Out of scope and deferred to phase 2B (per-module decisions, not bulk-applicable): - LOGGER_CATEGORY constants in each module's consts.ts must become the module's own LOG_CATEGORY (BUSS_LOG_CATEGORY = 'buss', CONN_LOG_CATEGORY = 'conn', etc.) — different rename per module, not a single sed pattern. - APP_* → AAPP_* (arts/aapp uses APP_ today; libs/aapp already uses AAPP_). - Ad-hoc constants without module prefix (DEFAULT_TIMER_*, EVENT_*, BROWSER_*, IDENTITY_*, ACTOR_*, REVOKE_SCOPE_*, etc. in arts/sess/consts.ts; AUTO_REAUTH_* in arts/conn). Note on web/ files: - src/web/routes/active/get-started/ai-agents/+page.svelte - src/web/routes/temp/c2/+page.svelte - src/web/routes/temp/c2/Curtain.svelte These three files contain pre-existing user modifications (work in progress unrelated to this rename) that the bulk sed touched on top because they referenced renamed identifiers. Excluding them would break compilation. Their content here is the intersection of both changes; the user's prior edits to these files are intentionally bundled in this commit. Verification: svelte-check 1395 files / 0 errors. Server 1230 tests, client 19 tests — all green. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
6908f82f09 |
Reorganize docs: move working/audit files to docs/ and add conventions
Working documents and audits were spread across the project root, mixing with standard npm/GitHub files (README, CHANGELOG, CONTRIBUTING, SECURITY, BRAND). Moves them under docs/ for a clean root and adds docs/conventions.md as the canonical document for codebase-wide naming and structure rules. Files moved to docs/ (via git mv, history preserved): - audit-1-5.md (current ecosystem audit) - AUDIT_KIMI.md - AUDIT_OPENCODE.md - AUDIT_claude.md (historical audits from prior tools) - before_0_1.md (pre-0.1 release checklist) - buss.md (bus design doc, no longer live) - NEXT_STEPS.md (roadmap) Files staying in root (npm/GitHub convention): - README.md, CHANGELOG.md, CONTRIBUTING.md, SECURITY.md, BRAND.md References updated to point at docs/: - CHANGELOG.md (line 11) - README.md (line 105) - SECURITY.md (line 3) - src/web/routes/active/security/+page.svelte (line 46) docs/conventions.md captures three rules accepted as binding for the codebase: 1. Module identifier — every artifact and lib uses its 4-letter alias (BUSS, CONN, SESS, PERM, TIMR, LOGR, CACH, STOR, FMTS, FEND, ADOM, AAPP, AUTH, LANG, HTTP, SIUM, ERRS) for both string values and constant name prefixes. Drift from this rule (BUS_*, CONNECTION_*, SESSION_*, …) is being closed in the next audit pass. 2. Constant naming — `<MOD>_<CATEGORY>_<NAME>` strictly. No exceptions (no DEFAULT_TIMER_* style). 3. Category vocabulary — fixed list of category tokens (ERR, EVENT, DIAGNOSTIC_EVENTS, METHOD, STATE, STATUS, KIND, REASON, TYPE, MODE, DEFAULT, LIMIT, ID_PREFIX, LOG_CATEGORY, LOG_MSG, ERROR_MSG, ERROR_NAME, CONTEXT_KEY). Ad-hoc categories (AUTO_REAUTH, AUTO_INVALIDATE, BUFFER_POLICY, CHANNEL_STATE) fold into one of these. The document also formalizes the layer rules and ErrCode shape that will be implemented in upcoming commits. svelte-check 1395/0 errors. No code-side regressions; the moves are file-only. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
743db4ccc1 |
Scope diagnostic event and method values with their owning module
audit-1-5.md section 2: 46 values were emitted as bare strings
(`'auth_failed'`, `'listener_threw'`, `'check'`) and collided across
artifacts in any aggregated log stream. Each value now carries its
module prefix so the type is self-describing in isolation and never
clashes with another emitter.
- arts/conn/consts.ts (CONNECTION_DIAGNOSTIC_EVENTS) — 15 values → conn.*
- arts/sess/consts.ts (SESSION_DIAGNOSTIC_EVENTS) — 15 values → sess.*
- arts/perm/consts.ts (PERMISSION_CLIENT_DIAGNOSTIC_EVENTS) — 3 → perm.client.*
- svrs/perm/consts.ts (PERMISSION_DIAGNOSTIC_EVENTS) — 3 → perm.server.*
- svrs/perm/consts.ts (PERMISSION_METHOD_*) — 7 → perm.* (aligns with
the client-side counterpart in arts/perm/consts.ts which already used
this scoping)
- libs/timers/consts.ts (TIMER_DIAGNOSTIC_EVENTS) — 3 values → timr.*
The rule was already documented in arts/perm/consts.ts ("scoped with
the artifact prefix `perm.` so that aggregated diagnostic streams do
not collide"); these six files were the modules that hadn't been
brought into compliance.
Real collisions resolved today: `'listener_threw'` (3 emitters: conn
+ sess + timr), `'session_revoked'` and `'session_expired'` (conn
bridge + sess lifecycle).
Consumers reference the constants by symbol (`CONNECTION_DIAGNOSTIC_EVENTS.AUTH_FAILED`,
not `'auth_failed'`), so this is a transparent rename. svelte-check
1395/0 errors; server 1230 tests; client 19 tests — all green.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
bf3891ca91 |
Decouple cross-artifact runtime imports and finalize bus contract
Layer-boundary cleanup (audit-1-5.md section 1): - fend → adom: move apply.ts to libs/dom; FrontendDom is now DomApplier; fend falls back to bare applyChange instead of constructing ActiveDom - sium → lang: full split — pure code (consts, types, guards, helpers, errors, json, plural, plural_rules, diagnostics) moves to libs/lang; arts/lang keeps engine + active wrappers and re-exports for back-compat - conn → timr: minimum split — types and public constants move to libs/timers; conn imports types from $libs/timers; EngineConnectionsOptions.timers is now required (no more silent createEngineTimers fallback). Tests updated to construct shared timers per beforeEach Bus contract finishing touches (continued from prior session): - subscribe() returns the unsubscribe function directly - publishCausedBy() propagates correlationId/causationId - invokeListener hook + Svelte adapter wraps listeners in untrack - maxReentrancyDepth guard with BusReentrancyLimitError (fatal — bypasses listener-error trap) - DEV-mode structuredClone payload check raising BusInvalidPayloadError - BusListenerFailure carries envelopeId/correlationId/causationId - createBusRecent active wrapper, bus-context.svelte.ts, APP_EVENT_RUNTIMES table with assertEventCanFire wired into every publishApp* helper - App switches to createSvelteEngineBus audit-1-5.md captures the full ecosystem audit (5 axes); section 1 is now closed by these changes. Sections 2-5 remain open. Verification: svelte-check 1395/0 errors; server 1230 tests passed; client 19 tests passed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
36868d3efe |
Add bus orchestration and ecosystem hardening
|
5 months ago |
|
|
e6e9c38f7c |
Prepare active 0.1 release gates
|
5 months ago |
|
|
eacf9e8e91 |
Add active ecosystem documentation
|
5 months ago |
|
|
111c9ae563 |
Document shared logger diagnostics contract
|
5 months ago |
|
|
8e74c5f309 |
Expand frontend docs and app integration tests
|
5 months ago |