@wade-development/security-core
v1.0.0
Published
Canonical security event schema shared by every Company security SDK and the ingest edge.
Readme
@wade-development/security-core
The canonical security event schema, shared by every Wade security SDK and by the platform's ingest edge.
You probably do not want to install this directly. Application authors use
@wade-development/security-node
(servers) or @wade-development/security-browser (pages), both of which depend on this
package. Install it on its own only if you are building a new SDK or validating
events before sending them.
npm install @wade-development/security-coreWhat it contains
- The
SecurityEventtype and its Zod schema - The event category enum and the
category.object.actionnaming validator schemaVersionand the set of versions the platform still accepts- The sensitive-field denylist, applied before any event leaves your process
- Metadata limits: maximum depth, string length and key count
- ULID event id generation — lexicographically sortable, monotonic within a millisecond
Two things worth knowing
Tenant identity is never sent. clientId, applicationId, environmentId,
tenantId, organizationId and credentialId are resolved server-side from
your API credential. The schema rejects them outright rather than stripping
them: a client sending one is either compromised or badly broken, and both
deserve to be visible.
The denylist runs before transmission. Fields whose names look like
passwords, tokens, cookies or authorization headers are removed inside your
process, not on arrival. Matching is token-based, so passwordConfirmation is
caught while keyId — which investigations need — is not.
Runtime
Platform-neutral. No Node-specific APIs, so it works in Node, Deno, Bun,
browsers and edge runtimes. Its only dependency is zod.
Licence
MIT — see the LICENSE file included in this package.
