@substrat-run/psl
v0.2.5
Published
Vendored Public Suffix List + the canonical matching algorithm — the registrable-suffix guard behind cookie-domain and custom-hostname validation (D-35). The list data is MPL-2.0 from publicsuffix.org; the code is AGPL-3.0.
Readme
@substrat-run/psl
A self-contained Public Suffix List guard for Substrat — dependency-free, web-standard only.
Full documentation: https://substrat.net/reference/psl
Why it exists
The registrable-suffix boundary is where one tenant's cookie could reach another. Enforcing it
needs the real Public Suffix List, not a label-count heuristic: acme.com is registrable, but
acme.co.uk sits one level deeper, and only the list knows the difference.
The list is vendored — checked in, no runtime fetch — so the guard runs unchanged in module code, a Worker, or Node.
API
import {
getPublicSuffix,
getRegistrableDomain,
isPublicSuffix,
sameRegistrableDomain,
normalizeHost,
PSL_VERSION,
} from '@substrat-run/psl';
isPublicSuffix('co.uk'); // true
getRegistrableDomain('app.acme.co.uk'); // 'acme.co.uk'
sameRegistrableDomain('a.acme.com', 'b.acme.com'); // truePSL_VERSION identifies the vendored snapshot.
Two callers
- The cookie-domain guard in
@substrat-run/vertical-auth— refuse to set a session cookie on a public suffix. - The control-plane bind check in
@substrat-run/control-plane-api— refuse to bind a custom hostname that is a bare public suffix.
Status
Pre-release (0.x): interfaces change without notice until the first vertical ships.
