产品精选

rauchg 开源 gdp-ts:用类型系统强制 API 权限校验

精选理由

rauchg 出了个 TypeScript 库 gdp-ts,把权限检查变成编译期类型证明,Agent 写的代码没做鉴权直接编译不过,挺适合当 AI 编码的安全护栏。

Vercel 创始人 Guillermo Rauch 发布 gdp-ts,这是一个库、linter 和 AI skill 的组合,用于更安全的 API 设计。它要求敏感函数必须携带'证明',证明调用方已执行授权检查,TypeScript 类型检查器会在编译期验证这些证明。README 以 Vercel 真实场景为例:修改 Project 密码需要特定角色和 entitlement 的证明。该模式源自 Haskell 社区的 'Ghosts of Departed Proofs' 研究思路,作者认为 AI Agent 大量写代码的时代让这种硬约束重新变得实用。

图片来源 · Guillermo Rauch
原文 · Guillermo Rauch

Introducing gdp-ts: Ghosts of Departed Proofs for TypeScript. gdp-ts is a library, linter and AI skill for safer API design. Under this contract, sensitive functions require 'proofs' that the caller performed an authorization check. The typechecker verifies these proofs at compile time, preventing your team and agents from shipping catastrophic security (and other kinds of) bugs. While these patterns have existed for quite some time, especially in ecosystems like Haskell, ① human code review and ② cognitive and syntactic overhead made these solutions niche. The situation is now inverted. Agents are writing more code than we can review, and they *thrive* in tight loops with hard constraints that would frustrate us. We see this with the rise of Rust, borrow checker, code aesthetics debate and all. The README and examples model a real-world Vercel API product constraint: changing the password on a Project requires a proof of a certain role + a certain entitlement. Thanks to Matt Noonan and Ollie Charles for their research in this space. github.com/rauchg/gdp-ts Your browser does not support the video tag. 🔗 View on Twitter 💬 0 🔄 0 ❤️ 2 👀 361 ⚡