@vigilkids/server-boundary
v0.1.1
Published
Server-only secret and request-topology trust-boundary primitives
Maintainers
Readme
@vigilkids/server-boundary
Server-only secret and request-topology trust-boundary primitives for BFF applications.
TrustedClientIpResolver compiles a finite CIDR allowlist once and resolves the
nearest untrusted address in an X-Forwarded-For chain.
NodeTrustedClientIpAdapter is the canonical Node request adapter: it reads the
socket peer and forwarding header, ignores spoofed forwarding data from
untrusted peers, and fails closed for malformed topology. Strict mode requires a
socket peer. Local-development mode permits only one forwarded loopback peer
when Nitro does not expose the socket address.
PrivateSecretResolver resolves bounded env://NAME references or absolute,
owner-only regular file:// references without following symbolic links. It is
the shared server boundary for session, vault, admission and signing secrets.
import {
NodeTrustedClientIpAdapter,
TrustedClientIpResolver,
} from '@vigilkids/server-boundary/server'
const resolver = new TrustedClientIpResolver(['127.0.0.0/8', '10.0.0.0/8'])
const adapter = new NodeTrustedClientIpAdapter({
mode: 'strict',
resolver,
})
const client = adapter.resolve(request)This package has no browser entry and does not provide trust-all or hop-count configuration.
