@aopslabs/host-admission
v0.1.2
Published
Immutable admission snapshots and fail-closed domain/operation gates for AOPS Labs plugin hosts.
Readme
@aopslabs/host-admission
Immutable admission snapshots and constant-time domain/operation checks for plugin hosts.
Installation
```bash npm install @aopslabs/host-admission ```
The package verifies signed release closures and South entitlement leases once, then projects immutable serving decisions. Commercial verification failures quarantine only the affected domain. Full, degraded, hard-expiry, migration/setup, and client-adapter decisions fail closed.
The customer-domain amendment adds a third, explicit customer plane. It accepts
only installation-owned receipts created by an authenticated tenant-admin action,
rechecks current package and operation-catalog bytes, requires a PoP-bound South
lease v3, and admits only the standard domain.operation surface. Customer
artifacts do not acquire publisher or vendor authenticity. HTTP extensions,
lifecycle hooks, manifest or adapter providers, remote sources, tolerant
bootstrap, disabled strict allowlists, and secret environment bindings fail
closed.
Customer quota changes are transactional. The package never chooses a sorted first-N subset. A same-authority over-quota candidate may preserve only an exact, signed last-known-good set bound to the current lease jti, entitlement epoch, revocation epoch, and receipt key. Cold starts, changed authority, stale state, or tampered state quarantine that customer authority without affecting community or commercial domains.
The source workspace remains installable against the published 0.2.0 trust
baseline for commercial-only verification. The reproducible TASK-180 candidate
smoke overlays the exact reviewed 0.3.0 tarball, runs the customer matrix, and
uses npm pack to produce @aopslabs/[email protected] with an exact
@aopslabs/[email protected] runtime dependency. Do not substitute
pnpm pack; the reviewed candidate digest is defined by npm pack bytes.
`createAllowAllAdmissionProvider` is intended only for community and development hosts.
License
Copyright (c) 2026 Mehmet Zeki Sönmez. Licensed under the PolyForm Strict License 1.0.0; see LICENSE.
