@lssm/integration.opa-calendar-bridge
v2.0.2
Published
Bridge adapting the real CalendarProvider (e.g. GoogleCalendarProvider from integration.provider-calendar) to the organization-planning module's CalendarExecutionAdapterPort. Port → provider; no new Google SDK code.
Downloads
97
Readme
@lssm/integration.opa-calendar-bridge
Bridge that binds the organization-planning module's
CalendarExecutionAdapterPort (kind: 'calendar_execution') to a real
CalendarProvider — without reimplementing any provider SDK. This is the
port→provider seam: the module declares the typed port; this package adapts it to
a concrete provider (e.g. the GoogleCalendarProvider owned by
@lssm/integration.provider-calendar).
Why it exists
OPA proposes bookings and agendas as fail-closed drafts. To actually execute a
confirmed booking (write a calendar event), the runtime needs a bound
calendar_execution adapter. This bridge provides one over an existing provider,
keeping Google and Microsoft Graph SDK/transport code out of the runtime and
the module.
Usage
import { createOpaCalendarExecutionBridge } from '@lssm/integration.opa-calendar-bridge';
import { GoogleCalendarProvider } from '@lssm/integration.provider-calendar/impls/google-calendar';
// Any CalendarProvider works (Google, a fake, a future provider).
const calendar = createOpaCalendarExecutionBridge(
new GoogleCalendarProvider({ auth })
);
// Or the convenience factory (./google):
import { createGoogleOpaCalendarExecutionBridge } from '@lssm/integration.opa-calendar-bridge/google';
const calendar = createGoogleOpaCalendarExecutionBridge({ auth });
// Outlook/Exchange via a host-authenticated Microsoft Graph client:
import { createMicrosoftGraphOpaCalendarExecutionBridge } from '@lssm/integration.opa-calendar-bridge/microsoft-graph';
const outlookCalendar = createMicrosoftGraphOpaCalendarExecutionBridge({ client });
// Bind into the OPA runtime so booking.confirm can write on the authorized path:
buildOpaOps({ rbac, calendar });Fail-closed posture
The bridge only forwards a method call when invoked. The OPA runtime invokes
createEvent exclusively on the authorized + approval-satisfied confirm path
(isOpaExecutionAllowed); every other path performs no external write.
Exports
| Subpath | Export |
| ----------- | --------------------------------------------------------- |
| . | generic bridge plus Google and Microsoft convenience factories |
| ./bridge | provider-agnostic bridge (no Google SDK) |
| ./google | Google convenience factory |
| ./microsoft-graph | Microsoft Outlook/Graph convenience factory |
createGoogleBookingProviderBridge is the booking-specific seam for the G015
known-ID saga port. A host-provided resolver supplies protected booking effect
details; the bridge forwards only provider-neutral create/get/cancel outcomes.
For an original create, the provider retains its deterministic tenant/booking ID
derivation. For a reschedule, the resolver must authorize the exact persisted
replacement ID and active replacement interval; the bridge forwards that known
ID unchanged for create and ambiguity recovery. Google SDK calls remain in
integration.provider-calendar.
The bridge also forwards normalized conference readiness without interpreting provider payloads. A Meet booking is not terminal until the provider reports a verified ready link; pending, ambiguous, or failed conference creation remains recoverable through exact known-ID lookup.
createOpaMeetingOccurrenceFingerprint projects calendar occurrences into
PII-free recorder-matching evidence. Its event digest uses the provider event id
shared by Google/Outlook and recorder metadata, while participant identities are
normalized, sorted, and digested. Calendar ids and participant addresses never
cross the OPA binding boundary.
