@aopslabs/host-core
v0.3.3
Published
A framework-neutral runtime for registering domain plugins, matching routes, applying access policies, and dispatching structured requests.
Readme
@aopslabs/host-core
A framework-neutral runtime for registering domain plugins, matching routes, applying access policies, and dispatching structured requests.
Installation
npm install @aopslabs/host-coreUsage
import {
DomainPluginRegistry,
dispatchDomainRequest
} from '@aopslabs/host-core';
const registry = new DomainPluginRegistry();
registry.register(contentPlugin);
const response = await dispatchDomainRequest({
registry,
request: {
method: 'POST',
domain: 'content',
path: ['documents', 'create'],
body: { title: 'Example' },
context: { tenantId: 'tenant-1' }
}
});Main surfaces
DomainPluginRegistryfor plugin registration and setupdispatchDomainRequestfor request routing and execution- Route matching against declarative manifests
- Public, authenticated, and role-based policies
- Additive authenticated-route requirements:
requiredCapabilitiesuses all-of semantics,requiredRolesuses any-of semantics, and both must pass when declared. Routes without these fields retain their existing behavior. - Plugin-contract and configuration validation
- Tool-provider adapters for catalog-driven invocation
- Opt-in
host.route-safety.v2manifests with an author-declaredgateClass(read,write, ordestructive). V2 declarations preserve raw domainsideEffectandpolicy.safetyevidence and fail closed when required fields conflict.
Plugins without the capability retain the legacy route contract. HTTP method or operation-name inference is never an authority for a v2 route.
The package has no runtime dependencies and does not require a particular HTTP framework.
License
Copyright (c) 2026 Mehmet Zeki Sönmez.
Licensed under the PolyForm Strict License 1.0.0. The license permits noncommercial use and does not grant permission to modify or redistribute the package.
