@astram/core
v1.2.0
Published
Astram framework — sealed security core (Identity, Authentication, Session, Risk, Authorization, Audit). ZERO framework deps — the portable decision brain (ADR-0003). The frozen public contract consumers build against; installed, not edited (ADR-0023).
Readme
@astram/core
The framework-agnostic security Core for Astram. Owned by the Core team
(STATUS layer 3, 010_Architecture). Framework-agnostic per
ADR-0003 — ZERO
NestJS / React / Express / Vite imports (enforced by the root ESLint boundary rule).
What this package is
The portable contract other layers build against. At this Scaffold step it defines types/interfaces only — the engine seams and the module-registers-metadata contract. No security logic lives here yet; each layer's implementation is built later, against these seams.
Engine seams (one per layer — the request's journey)
| Layer | Module | Key exports |
| -------------- | -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Identity | src/identity | Principal, Tenant, PrincipalKind, ExternalIdentityAssertion, IdentityBroker |
| Authentication | src/authentication | Credential, AuthFactor, AuthenticationResult, Authenticator |
| Session | src/session | Session, SessionTokens, SessionEstablishment, SessionAuthority |
| Risk | src/risk | RiskSignal, RiskScore, RiskLevel, RiskEngine |
| Authorization | src/authorization | Principal-based Action, Resource, DecisionContext, Decision, DecisionReasonCode, AccessTier, ResourceLevel, DecisionAuthority.decide(principal, action, resource, context) (§7) |
| Audit | src/audit | AuditEvent, AuditEventType, AuditSink |
Module-registers-metadata contract
src/metadata — how a business module declares its object types, actions,
access tiers, and supporting read-only dependencies to the Core (it never
implements access checks). Exports ObjectTypeDescriptor, FieldDescriptor,
ActionDescriptor, SupportingDependency, ModuleMetadata, and the
ModuleRegistry interface (static + dynamic/runtime registration, per ADR-0014 §5.5).
Scripts
pnpm --filter @astram/core build # tsc → dist/ (declarations + maps)
pnpm --filter @astram/core lint # eslint — proves no framework import leaked
pnpm --filter @astram/core test # vitest — trivial import smoke testRules
- No framework imports anywhere (ADR-0003). Inject platform deps across the integration boundary instead.
- Types only at this step — no decision/auth/session logic bodies. Real invariant proofs are authored per-layer as those layers are built.
