@projectpac/core-api
v0.6.0
Published
Part of PAC: @projectpac/core-api.
Downloads
820
Readme
@projectpac/core-api
Claims ctx.api. One control API over HTTP, many faces: a CLI, a GUI, an MCP
server are all clients of it.
- Core routes are reserved by construction. The node's own routes -- health
and metrics, the traces, the principal's views of its sessions, peers and
runs, and the whole install lifecycle -- are registered on the server;
everything a plugin serves lives under
/flows/:plugin/*and is dispatched from a table, so no plugin has a path with which to claim a core route. The table exists because fastify's router is fixed once it listens, while plugins come and go. - A route is an effect of the plugin that declared it.
handlederives the caller, refuses a path that caller's manifest did not declare, and registers through the caller's own fiber -- so the routes a principal approved when they installed it are the routes it can serve, and disabling the plugin withdraws them with no uninstall path of its own. - A reachable node must prove who is calling.
assertSafeBindingrefuses at load when a non-loopback bind carries no token, the daemon runs the same refusal in its preflight, and requests from an origin the operator did not configure are refused even when they hold a token. - Bounds on both directions. Request bodies are bounded by fastify, a plugin's response by its serialized size, and concurrent plugin handlers by a count.
