最高第 1 名 已下榜
gdp-ts类型安全库发布
Guillermo Rauch发布gdp-ts库与linter,用'证明'机制在编译期校验API授权检查。
要点
- @rauchg 发布 gdp-ts,称其是一个用于更安全 API 设计的库、linter 和 AI skill。
- 在 gdp-ts 的契约下,敏感函数需要调用方提供已执行授权检查的“proof”,由类型检查器在编译时验证。
- README 和示例模拟了一个真实世界的 Vercel API 产品约束:修改 Project 密码需要特定角色加特定权益的 proof。
- @rauchg 感谢 Matt Noonan 和 Ollie Charles 在这一领域的研究。
要点和反应摘要由 AI 依据本页推文整理,请以原推为准。 我们怎么用 AI
原推
Introducing gdp-ts: Ghosts of Departed Proofs for TypeScript.
gdp-ts is a library, linter and AI skill for safer API design. Under this contract, sensitive functions require 'proofs' that the caller performed an authorization check.
The typechecker verifies these proofs at compile time, preventing your team and agents from shipping catastrophic security (and other kinds of) bugs.
While these patterns have existed for quite some time, especially in ecosystems like Haskell, ① human code review and ② cognitive and syntactic overhead made these solutions niche.
The situation is now inverted. Agents are writing more code than we can review, and they *thrive* in tight loops with hard constraints that would frustrate us. We see this with the rise of Rust, borrow checker, code aesthetics debate and all.
The README and examples model a real-world Vercel API product constraint: changing the password on a Project requires a proof of a certain role + a certain entitlement. Thanks to Matt Noonan and Ollie Charles for their research in this space.
https://t.co/eRWdiMvQ2V
讨论 0
注册 登录 后参与讨论
还没有人讨论,来说第一句。