Peaked at #1 Off the board
gdp-ts type-safety library released
Guillermo Rauch released gdp-ts, a library and linter using proofs to verify API authorization checks at compile time.
Key points
- @rauchg introduced gdp-ts, described as a library, linter and AI skill for safer API design.
- Under gdp-ts's contract, sensitive functions require 'proofs' that the caller performed an authorization check, verified by the typechecker at compile time.
- The README and examples model a Vercel API product constraint: changing the password on a Project requires a proof of a certain role plus a certain entitlement.
- @rauchg credits Matt Noonan and Ollie Charles for their research in this space.
Key points and the reaction summary are written by AI from the posts on this page. Check the original post. How we use AI
Original post
Introducing gdp-ts: Ghosts of Departed Proofs for TypeScript.
gdp-ts is a library, linter and AI skill for safer API design. Under this contract, sensitive functions require 'proofs' that the caller performed an authorization check.
The typechecker verifies these proofs at compile time, preventing your team and agents from shipping catastrophic security (and other kinds of) bugs.
While these patterns have existed for quite some time, especially in ecosystems like Haskell, ① human code review and ② cognitive and syntactic overhead made these solutions niche.
The situation is now inverted. Agents are writing more code than we can review, and they *thrive* in tight loops with hard constraints that would frustrate us. We see this with the rise of Rust, borrow checker, code aesthetics debate and all.
The README and examples model a real-world Vercel API product constraint: changing the password on a Project requires a proof of a certain role + a certain entitlement. Thanks to Matt Noonan and Ollie Charles for their research in this space.
https://t.co/eRWdiMvQ2V
Top replies on X
Sign in to see 5 top replies from X
From @cramforce, @maria_rcks, @udohjeremiah_ and others. Spam removed, with English and Chinese translations.
Discussion 0
Sign up Sign in to join the discussion
No comments yet. Start the conversation.