@nexart/consequential-execution
v0.1.0
Published
Strict, hash-bound consequential execution evidence
Readme
@nexart/consequential-execution
Phase 1 standalone CER support for consequential actions. The package records producer-reported evidence; it does not authenticate the producer, prove that an action was authorised, or assert that a target, state, outcome, or decision reference is true. Every accepted semantic field is schema-validated and covered by the JCS certificate hash.
The API is intentionally family-specific: use createSnapshot, sealCer,
verifyCer, and their explicit async/confidential counterparts. Confidential
mode is opt-in ({ confidential: true, fields: [...] }); salts are returned
as separate openings and are never written to a CER. action records the
attempted or intended action. appliedChange records the change actually
applied: it is required for applied and partial, and forbidden for
failed. postState is a producer-reported observation, not causal proof.
decisionRefs is confidential as one whole field: its complete original array
is opened together, and indexed decisionRef:n fields are not supported;
array-position binding is not applicable because the whole array and its order
are committed together. Confidentiality
hides decision references from the public CER; it does not authenticate them.
SCHEMA_VERSION is 1; the certificate envelope's deliberate bundle
version is 0.1. A verification result's producer identity is always
CLAIM_ONLY: producer is reported by the producer and is never
cryptographically authenticated by this package. JCS uses UTF-8 RFC 8785
canonical member ordering under fixed protocol version 1.3.1.
Certificate and fixture-vector constants in tests are immutable compatibility claims. They must not be regenerated to make a failing test pass; changes require an intentional protocol/schema review.
