npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@obversa/surface

v0.1.1

Published

One secure local surface session.

Readme

@obversa/surface

This package runs one secure local surface session: a small user interface for one decision. It owns the loopback server, the session lifecycle, and the handoff of exactly one opaque result. It owns no callback state, no routing, and no run records.

Extracted from the skills-manager donor. Nothing of that product's inventory, graph, or editing behaviour survives here.

Install

pnpm add @obversa/surface

What the package gives

  • runSurface({...}) — the one launcher: it starts the session, places the page in the selected host, reports the url through ready, waits for the single decision, frames it on stdout, and shuts down. Signals interrupt cleanly. Pass signal: AbortSignal to interrupt it when its caller cancels. examples/hello-surface.mjs runs it end to end.
  • startSurface({ app, assets, api, ... }) — one loopback server on an ephemeral 127.0.0.1 port. The page URL carries a fragment token. Every API request must send it as a bearer token, checked in constant time. Requests with a wrong Host are refused, and state-changing requests with a wrong Origin are refused (a GET carries no Origin to check). JSON bodies are bounded at 4 MiB. Responses carry strict security headers, and response values pass secret redaction by default; a handler that returns { verbatim: true } sends its body byte-exact, as session.complete does with its verbatim option (below).
  • Payloads pass secret redaction by default. session.complete(payload, { verbatim: true }) is the explicit opt-in for content that must survive byte-exact — review annotations quoting code, for example — and the caller owns what it carries.
  • One terminal decision per session: the app completes it, the user cancels it, the lease or session times out, or the caller interrupts. waitForDecision() resolves with one result and the browser acknowledges it, with a timeout when the acknowledgement never comes.
  • frameResult / parseFramedResult — the framed stdout handoff with app-named frames, so one caller can demultiplex surfaces.
  • createPrivateTransfer — private temporary files (0700 directory, 0600 files) with SHA-256 hashes in the manifest. removeTransfer removes only directories this module created.
  • @obversa/surface/client — the no-framework browser kit: token handling, authenticated fetch, heartbeat, submit and cancel with acknowledgement.
  • openSurfaceUrl — host placement: the command the host injected as $OBVERSA_SURFACE_BIN first, run only when it is an absolute path (it receives a one-time launch URL that redirects to the page — the token never enters a process argument — and nothing is looked up on PATH; the cmux review command sets it to the glue beside itself), the platform browser by its system path second, a printed URL last. Diagnostics stay on stderr; stdout belongs to the framed result.

Test

node --test test/*.test.mjs

The suite runs real HTTP sessions against the loopback server. No UI opens and nothing external is called.

Rules

  • No dependency on Obversa records, or one required host.
  • Short surface sessions only; no long-lived viewer lifecycle.
  • A surface returns one opaque result. The caller interprets it.