NoFOMO
搜索 中EN 登录 注册

最高第 1 名 已下榜

gdp-ts类型安全库发布

Guillermo Rauch发布gdp-ts库与linter,用'证明'机制在编译期校验API授权检查。

名次变化

要点

  • @rauchg 发布 gdp-ts,称其是一个用于更安全 API 设计的库、linter 和 AI skill。
  • 在 gdp-ts 的契约下,敏感函数需要调用方提供已执行授权检查的“proof”,由类型检查器在编译时验证。
  • README 和示例模拟了一个真实世界的 Vercel API 产品约束:修改 Project 密码需要特定角色加特定权益的 proof。
  • @rauchg 感谢 Matt Noonan 和 Ollie Charles 在这一领域的研究。

要点和反应摘要由 AI 依据本页推文整理,请以原推为准。 我们怎么用 AI

原推

Guillermo Rauch @rauchg 90.1万 粉丝

Introducing gdp-ts: Ghosts of Departed Proofs for TypeScript. gdp-ts is a library, linter and AI skill for safer API design. Under this contract, sensitive functions require 'proofs' that the caller performed an authorization check. The typechecker verifies these proofs at compile time, preventing your team and agents from shipping catastrophic security (and other kinds of) bugs. While these patterns have existed for quite some time, especially in ecosystems like Haskell, ① human code review and ② cognitive and syntactic overhead made these solutions niche. The situation is now inverted. Agents are writing more code than we can review, and they *thrive* in tight loops with hard constraints that would frustrate us. We see this with the rise of Rust, borrow checker, code aesthetics debate and all. The README and examples model a real-world Vercel API product constraint: changing the password on a Project requires a proof of a certain role + a certain entitlement. Thanks to Matt Noonan and Ollie Charles for their research in this space. https://t.co/eRWdiMvQ2V
推文配图
2,384点赞 123转发 170回复 25万浏览

在 X 上查看 收藏

X 上的热门回复

登录后查看 X 上的 5 条热门回复

来自 @cramforce, @maria_rcks, @udohjeremiah_ 等,已过滤广告,附中英文翻译。

免费注册 已有账号?登录

讨论 0

还没有人讨论,来说第一句。

推荐信源

觉得我们漏了哪个一手信源,或者该关注什么话题?告诉我们。审核通过后,所有人的榜单都会覆盖到它。

@用户名,或者主页链接