feat(housekeeping): dispatch audited commands

This commit is contained in:
Simo committed 2026-08-27 18:30:44 +02:00
1 parent ca666d9f90
commit 6aed71a8b2
8 files changed
+996

No files matched your search

+112
View File
@@ -0,0 +1,112 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
import { z } from "zod";
import { registerHousekeepingCommand } from "@/features/housekeeping/foundation/commands/registry";
import {
anyCapability,
ok,
} from "@/features/housekeeping/foundation/contracts";
import type { AuditEntry } from "@/lib/services/audit";
const { auditEntries, context, rateLimitCalls } = vi.hoisted(() => ({
auditEntries: [] as AuditEntry[],
context: {
actor: { id: 71, username: "server-operator", rank: 4 },
isSuperAdmin: false,
has: (slug: string) => slug === "admin.settings.edit",
hasAny: (...slugs: string[]) => slugs.includes("admin.settings.edit"),
hasAll: (...slugs: string[]) =>
slugs.every((slug) => slug === "admin.settings.edit"),
},
rateLimitCalls: [] as Array<[string, number, number]>,
}));
vi.mock("@/features/housekeeping/foundation/server-capability-context", () => ({
getHousekeepingCapabilityContext: async () => context,
}));
vi.mock("@/lib/services/audit", () => ({
housekeepingAuditWriter: {
write: async (entry: AuditEntry) => {
auditEntries.push({ ...entry });
},
},
}));
vi.mock("@/lib/rate-limit", () => ({
clientIp: async () => "203.0.113.7",
rateLimit: async (key: string, attempts: number, windowMs: number) => {
rateLimitCalls.push([key, attempts, windowMs]);
return { ok: true, retryAfter: 0 };
},
}));
import { executeHousekeepingCommand } from "./housekeeping-command";
registerHousekeepingCommand({
id: "system.server-action.serializable",
owner: "system",
risk: "safe",
capability: anyCapability("admin.settings.edit"),
input: z.object({ value: z.string() }),
requiresReason: false,
rateLimit: { attempts: 5, windowMs: 120_000 },
execute: async (commandContext, input) =>
ok(
{
value: input.value,
actorId: commandContext.capability.actor.id,
ipAddress: commandContext.ipAddress,
},
commandContext.correlationId,
),
});
beforeEach(() => {
auditEntries.length = 0;
rateLimitCalls.length = 0;
});
describe("executeHousekeepingCommand", () => {
it("accepts a plain request and ignores spoofed server-owned metadata", async () => {
const request = {
commandId: "system.server-action.serializable",
input: { value: "saved" },
risk: "sensitive",
owner: "people",
capability: { mode: "any", slugs: ["forged.permission"] },
actor: { id: 999 },
ipAddress: "198.51.100.9",
rateLimit: { attempts: 999, windowMs: 1 },
audit: { action: "forged.action", target: "forged-target" },
};
const result = await executeHousekeepingCommand(request);
expect(result).toMatchObject({
ok: true,
data: {
value: "saved",
actorId: 71,
ipAddress: "203.0.113.7",
},
});
expect(rateLimitCalls).toEqual([
[
"housekeeping-command:71:203.0.113.7:system.server-action.serializable",
5,
120_000,
],
]);
expect(auditEntries).toMatchObject([
{
userId: 71,
action: "system.server-action.serializable",
target: "system",
domain: "system",
ipAddress: "203.0.113.7",
outcome: "success",
},
]);
expect(auditEntries[0]?.correlationId).toBe(result.correlationId);
});
});
+27
View File
@@ -0,0 +1,27 @@
"use server";
import {
dispatchHousekeepingCommand,
type HousekeepingCommandRequest,
} from "@/features/housekeeping/foundation/commands/dispatcher";
import type { HousekeepingResult } from "@/features/housekeeping/foundation/contracts";
import { getHousekeepingCapabilityContext } from "@/features/housekeeping/foundation/server-capability-context";
import { clientIp, rateLimit } from "@/lib/rate-limit";
import { housekeepingAuditWriter } from "@/lib/services/audit";
export async function executeHousekeepingCommand(
request: HousekeepingCommandRequest,
): Promise<HousekeepingResult<unknown>> {
const [context, ipAddress] = await Promise.all([
getHousekeepingCapabilityContext(),
clientIp(),
]);
return dispatchHousekeepingCommand(request, {
context,
ipAddress,
audit: housekeepingAuditWriter,
rateLimit: async (key, attempts, windowMs) =>
(await rateLimit(key, attempts, windowMs)).ok,
});
}
@@ -0,0 +1,78 @@
import { describe, expect, it } from "vitest";
import { z } from "zod";
import { anyCapability, ok } from "../contracts";
import { confirmHousekeepingCommand } from "./confirmation";
import type { HousekeepingCommand } from "./registry";
function command(
requiresReason: boolean,
risk: "safe" | "sensitive",
): HousekeepingCommand<Record<string, never>, null> {
return {
id: "system.confirmation.test",
owner: "system",
risk,
capability: anyCapability("admin.settings.edit"),
input: z.object({}),
requiresReason,
rateLimit: { attempts: 2, windowMs: 60_000 },
execute: async (context) => ok(null, context.correlationId),
};
}
describe("housekeeping command confirmation", () => {
it("rejects blank reasons when the registered command requires one", () => {
expect(
confirmHousekeepingCommand(
command(true, "sensitive"),
" \t ",
"corr-reason-missing",
),
).toEqual({
ok: false,
error: {
code: "VALIDATION",
messageKey: "errors.housekeeping.validation",
fieldErrors: { reason: ["errors.validation.required"] },
},
correlationId: "corr-reason-missing",
});
});
it("derives confirmation risk from the registered command and normalizes its reason", () => {
expect(
confirmHousekeepingCommand(
command(true, "sensitive"),
" Scheduled maintenance ",
"corr-confirm",
),
).toEqual({
ok: true,
data: {
commandId: "system.confirmation.test",
risk: "sensitive",
requiresReason: true,
reason: "Scheduled maintenance",
},
correlationId: "corr-confirm",
});
});
it("omits an empty optional reason without inventing confirmation metadata", () => {
const result = confirmHousekeepingCommand(
command(false, "safe"),
undefined,
"corr-safe",
);
expect(result).toEqual({
ok: true,
data: {
commandId: "system.confirmation.test",
risk: "safe",
requiresReason: false,
},
correlationId: "corr-safe",
});
});
});
@@ -0,0 +1,32 @@
import { fail, type HousekeepingResult, ok } from "../contracts";
import type { HousekeepingCommand } from "./registry";
export interface HousekeepingCommandConfirmation {
commandId: string;
risk: "safe" | "sensitive";
requiresReason: boolean;
reason?: string;
}
export function confirmHousekeepingCommand(
command: HousekeepingCommand<unknown, unknown>,
reason: string | undefined,
correlationId: string,
): HousekeepingResult<HousekeepingCommandConfirmation> {
const normalizedReason = reason?.normalize("NFC").trim() || undefined;
if (command.requiresReason && !normalizedReason) {
return fail("VALIDATION", "errors.housekeeping.validation", correlationId, {
reason: ["errors.validation.required"],
});
}
return ok(
{
commandId: command.id,
risk: command.risk,
requiresReason: command.requiresReason,
...(normalizedReason === undefined ? {} : { reason: normalizedReason }),
},
correlationId,
);
}
@@ -0,0 +1,395 @@
import { describe, expect, it } from "vitest";
import { z } from "zod";
import type { AuditEntry, HousekeepingAuditWriter } from "@/lib/services/audit";
import type { HousekeepingCapabilityContext } from "../contracts";
import { anyCapability, fail, ok } from "../contracts";
import { dispatchHousekeepingCommand } from "./dispatcher";
import {
type HousekeepingCommand,
registerHousekeepingCommand,
} from "./registry";
const actor = { id: 42, username: "operator", rank: 9 };
function capabilityContext(
granted: readonly string[] = ["admin.settings.edit"],
): HousekeepingCapabilityContext {
const permissions = new Set(granted);
return {
actor,
isSuperAdmin: false,
has: (slug) => permissions.has(slug),
hasAny: (...slugs) => slugs.some((slug) => permissions.has(slug)),
hasAll: (...slugs) => slugs.every((slug) => permissions.has(slug)),
};
}
function auditRecorder(events: string[] = []): {
entries: AuditEntry[];
writer: HousekeepingAuditWriter;
} {
const entries: AuditEntry[] = [];
return {
entries,
writer: {
write: async (entry) => {
entries.push({ ...entry });
events.push(`audit:${entry.outcome}`);
},
},
};
}
function dependencies(options?: {
context?: HousekeepingCapabilityContext;
ipAddress?: string;
audit?: HousekeepingAuditWriter;
rateLimit?: (
key: string,
attempts: number,
windowMs: number,
) => Promise<boolean>;
}) {
return {
context: options?.context ?? capabilityContext(),
ipAddress: options?.ipAddress ?? "198.51.100.8",
audit: options?.audit ?? auditRecorder().writer,
rateLimit: options?.rateLimit ?? (async () => true),
};
}
function register<I, O>(command: HousekeepingCommand<I, O>): void {
registerHousekeepingCommand(command);
}
function baseCommand<I, O>(
id: string,
overrides: Pick<HousekeepingCommand<I, O>, "input" | "execute"> &
Partial<
Pick<HousekeepingCommand<I, O>, "risk" | "requiresReason" | "rateLimit">
>,
): HousekeepingCommand<I, O> {
return {
id,
owner: "system",
risk: overrides.risk ?? "safe",
capability: anyCapability("admin.settings.edit"),
input: overrides.input,
requiresReason: overrides.requiresReason ?? false,
rateLimit: overrides.rateLimit ?? { attempts: 3, windowMs: 45_000 },
execute: overrides.execute,
};
}
describe("dispatchHousekeepingCommand", () => {
it("returns a typed not-found result for an unknown command", async () => {
const result = await dispatchHousekeepingCommand(
{ commandId: "system.missing", input: {} },
dependencies(),
);
expect(result).toMatchObject({
ok: false,
error: {
code: "NOT_FOUND",
messageKey: "errors.housekeeping.notFound",
},
});
expect(result.correlationId).toMatch(/^[0-9a-f-]{36}$/i);
});
it("rechecks capability without treating actor rank as authorization", async () => {
let executed = false;
const audit = auditRecorder();
register(
baseCommand("system.dispatch.denied", {
risk: "sensitive",
input: z.object({}),
execute: async (context) => {
executed = true;
return ok(null, context.correlationId);
},
}),
);
const result = await dispatchHousekeepingCommand(
{ commandId: "system.dispatch.denied", input: {} },
dependencies({ context: capabilityContext([]), audit: audit.writer }),
);
expect(result).toMatchObject({
ok: false,
error: { code: "FORBIDDEN" },
});
expect(executed).toBe(false);
expect(audit.entries.map((entry) => entry.outcome)).toEqual([
"intent",
"denied",
]);
expect(audit.entries[0]?.correlationId).toBe(result.correlationId);
expect(audit.entries[1]?.correlationId).toBe(result.correlationId);
});
it("rejects invalid input before the command can execute", async () => {
let executed = false;
register(
baseCommand("system.dispatch.invalid-input", {
input: z.object({ count: z.number().int().positive() }),
execute: async (context) => {
executed = true;
return ok(null, context.correlationId);
},
}),
);
const result = await dispatchHousekeepingCommand(
{ commandId: "system.dispatch.invalid-input", input: { count: -1 } },
dependencies(),
);
expect(result).toMatchObject({
ok: false,
error: { code: "VALIDATION" },
});
expect(executed).toBe(false);
});
it("rejects a missing required reason before the command can execute", async () => {
let executed = false;
const audit = auditRecorder();
register(
baseCommand("system.dispatch.reason", {
risk: "sensitive",
requiresReason: true,
input: z.object({}),
execute: async (context) => {
executed = true;
return ok(null, context.correlationId);
},
}),
);
const result = await dispatchHousekeepingCommand(
{ commandId: "system.dispatch.reason", input: {}, reason: " " },
dependencies({ audit: audit.writer }),
);
expect(result).toMatchObject({
ok: false,
error: {
code: "VALIDATION",
fieldErrors: { reason: ["errors.validation.required"] },
},
});
expect(executed).toBe(false);
expect(audit.entries.map((entry) => entry.outcome)).toEqual([
"intent",
"denied",
]);
});
it("uses actor, IP, command ID, and the approved command limit", async () => {
const calls: Array<[string, number, number]> = [];
let executed = false;
register(
baseCommand("system.dispatch.rate-limit", {
input: z.object({}),
rateLimit: { attempts: 2, windowMs: 90_000 },
execute: async (context) => {
executed = true;
return ok(null, context.correlationId);
},
}),
);
const result = await dispatchHousekeepingCommand(
{ commandId: "system.dispatch.rate-limit", input: {} },
dependencies({
rateLimit: async (key, attempts, windowMs) => {
calls.push([key, attempts, windowMs]);
return false;
},
}),
);
expect(calls).toEqual([
[
"housekeeping-command:42:198.51.100.8:system.dispatch.rate-limit",
2,
90_000,
],
]);
expect(result).toMatchObject({
ok: false,
error: { code: "RATE_LIMITED" },
});
expect(executed).toBe(false);
});
it("executes a safe command with parsed input and writes one success outcome", async () => {
const audit = auditRecorder();
let receivedCount = 0;
register(
baseCommand("system.dispatch.safe-success", {
input: z.object({ count: z.coerce.number().int().positive() }),
execute: async (_context, input) => {
receivedCount = input.count;
return ok({ doubled: input.count * 2 }, "wrong-command-correlation");
},
}),
);
const result = await dispatchHousekeepingCommand(
{ commandId: "system.dispatch.safe-success", input: { count: "4" } },
dependencies({ audit: audit.writer }),
);
expect(receivedCount).toBe(4);
expect(result).toMatchObject({ ok: true, data: { doubled: 8 } });
expect(audit.entries.map((entry) => entry.outcome)).toEqual(["success"]);
expect(audit.entries[0]?.correlationId).toBe(result.correlationId);
expect(result.correlationId).not.toBe("wrong-command-correlation");
});
it("persists sensitive intent before execution and success afterward", async () => {
const events: string[] = [];
const audit = auditRecorder(events);
let executionCorrelation = "";
register(
baseCommand("system.dispatch.sensitive-success", {
risk: "sensitive",
requiresReason: true,
input: z.object({ enabled: z.boolean() }),
execute: async (context) => {
executionCorrelation = context.correlationId;
events.push("execute");
return ok({ saved: true }, "untrusted-command-correlation");
},
}),
);
const result = await dispatchHousekeepingCommand(
{
commandId: "system.dispatch.sensitive-success",
input: { enabled: true },
reason: " Planned change ",
},
dependencies({ audit: audit.writer }),
);
expect(events).toEqual(["audit:intent", "execute", "audit:success"]);
expect(audit.entries).toMatchObject([
{
userId: 42,
action: "system.dispatch.sensitive-success",
target: "system",
domain: "system",
reason: "Planned change",
ipAddress: "198.51.100.8",
outcome: "intent",
},
{ outcome: "success" },
]);
expect(executionCorrelation).toBe(result.correlationId);
expect(audit.entries[0]?.correlationId).toBe(result.correlationId);
expect(audit.entries[1]?.correlationId).toBe(result.correlationId);
});
it("persists sensitive failure after execution with the same correlation", async () => {
const events: string[] = [];
const audit = auditRecorder(events);
register(
baseCommand("system.dispatch.sensitive-failure", {
risk: "sensitive",
input: z.object({}),
execute: async () => {
events.push("execute");
return fail(
"DEPENDENCY_UNAVAILABLE",
"errors.housekeeping.dependencyUnavailable",
"wrong-command-correlation",
);
},
}),
);
const result = await dispatchHousekeepingCommand(
{ commandId: "system.dispatch.sensitive-failure", input: {} },
dependencies({ audit: audit.writer }),
);
expect(events).toEqual(["audit:intent", "execute", "audit:failure"]);
expect(result).toMatchObject({
ok: false,
error: { code: "DEPENDENCY_UNAVAILABLE" },
});
expect(audit.entries[0]?.correlationId).toBe(result.correlationId);
expect(audit.entries[1]?.correlationId).toBe(result.correlationId);
});
it("blocks sensitive execution when intent persistence fails", async () => {
let executed = false;
register(
baseCommand("system.dispatch.intent-failure", {
risk: "sensitive",
input: z.object({}),
execute: async (context) => {
executed = true;
return ok(null, context.correlationId);
},
}),
);
const result = await dispatchHousekeepingCommand(
{ commandId: "system.dispatch.intent-failure", input: {} },
dependencies({
audit: {
write: async () => {
throw new Error("audit credentials exposed");
},
},
}),
);
expect(executed).toBe(false);
expect(result).toMatchObject({
ok: false,
error: {
code: "INTERNAL",
messageKey: "errors.housekeeping.internal",
},
});
});
it("sanitizes unknown exceptions and records a failure outcome", async () => {
const audit = auditRecorder();
register(
baseCommand("system.dispatch.exception", {
risk: "sensitive",
input: z.object({}),
execute: async () => {
throw new Error("database password=hunter2");
},
}),
);
const result = await dispatchHousekeepingCommand(
{ commandId: "system.dispatch.exception", input: {} },
dependencies({ audit: audit.writer }),
);
expect(result).toMatchObject({
ok: false,
error: {
code: "INTERNAL",
messageKey: "errors.housekeeping.internal",
},
});
expect(JSON.stringify(result)).not.toContain("hunter2");
expect(audit.entries.map((entry) => entry.outcome)).toEqual([
"intent",
"failure",
]);
expect(audit.entries[1]?.correlationId).toBe(result.correlationId);
});
});
@@ -0,0 +1,224 @@
import type { AuditEntry, HousekeepingAuditWriter } from "@/lib/services/audit";
import { satisfiesCapability } from "../capability-context";
import {
fail,
type HousekeepingCapabilityContext,
type HousekeepingResult,
mapUnknownError,
} from "../contracts";
import { createCorrelationId } from "../correlation";
import { writeIntent, writeOutcome } from "./audit-envelope";
import { confirmHousekeepingCommand } from "./confirmation";
import {
getHousekeepingCommand,
type HousekeepingCommand,
type HousekeepingCommandContext,
} from "./registry";
export interface HousekeepingCommandRequest {
commandId: string;
input: unknown;
reason?: string;
}
export interface HousekeepingCommandDependencies {
context: HousekeepingCapabilityContext;
ipAddress: string;
audit: HousekeepingAuditWriter;
rateLimit(key: string, attempts: number, windowMs: number): Promise<boolean>;
}
export async function dispatchHousekeepingCommand(
request: HousekeepingCommandRequest,
dependencies: HousekeepingCommandDependencies,
): Promise<HousekeepingResult<unknown>> {
const correlationId = createCorrelationId();
const command = getHousekeepingCommand(request.commandId);
if (!command) {
return fail("NOT_FOUND", "errors.housekeeping.notFound", correlationId);
}
const reason =
typeof request.reason === "string"
? request.reason.normalize("NFC").trim() || undefined
: undefined;
const auditEntry = createAuditEntry(
command,
dependencies.context,
dependencies.ipAddress,
correlationId,
reason,
);
if (command.risk === "sensitive") {
try {
await writeIntent(dependencies.audit, auditEntry);
} catch (error) {
return mapUnknownError(error, correlationId);
}
}
if (!satisfiesCapability(dependencies.context, command.capability)) {
return finishWithAudit(
dependencies.audit,
auditEntry,
"denied",
fail("FORBIDDEN", "errors.housekeeping.forbidden", correlationId),
correlationId,
);
}
const parsedInput = command.input.safeParse(request.input);
if (!parsedInput.success) {
const fieldErrors: Record<string, readonly string[]> = {};
for (const issue of parsedInput.error.issues) {
const field = String(issue.path[0] ?? "input");
fieldErrors[field] = ["errors.validation.invalid"];
}
return finishWithAudit(
dependencies.audit,
auditEntry,
"denied",
fail(
"VALIDATION",
"errors.housekeeping.validation",
correlationId,
fieldErrors,
),
correlationId,
);
}
const confirmation = confirmHousekeepingCommand(
command,
reason,
correlationId,
);
if (!confirmation.ok) {
return finishWithAudit(
dependencies.audit,
auditEntry,
"denied",
confirmation,
correlationId,
);
}
let allowed: boolean;
try {
allowed = await dependencies.rateLimit(
createRateLimitKey(
command.id,
dependencies.context,
dependencies.ipAddress,
),
command.rateLimit.attempts,
command.rateLimit.windowMs,
);
} catch (error) {
return finishWithAudit(
dependencies.audit,
auditEntry,
"failure",
mapUnknownError(error, correlationId),
correlationId,
);
}
if (!allowed) {
return finishWithAudit(
dependencies.audit,
auditEntry,
"denied",
fail("RATE_LIMITED", "errors.housekeeping.rateLimited", correlationId),
correlationId,
);
}
const commandContext: HousekeepingCommandContext = {
capability: dependencies.context,
correlationId,
ipAddress: dependencies.ipAddress,
};
let result: HousekeepingResult<unknown>;
try {
result = await command.execute(commandContext, parsedInput.data);
} catch (error) {
return finishWithAudit(
dependencies.audit,
auditEntry,
"failure",
mapUnknownError(error, correlationId),
correlationId,
);
}
const correlatedResult = withCorrelation(result, correlationId);
return finishWithAudit(
dependencies.audit,
auditEntry,
outcomeFor(correlatedResult),
correlatedResult,
correlationId,
);
}
function createAuditEntry(
command: HousekeepingCommand<unknown, unknown>,
context: HousekeepingCapabilityContext,
ipAddress: string,
correlationId: string,
reason: string | undefined,
): AuditEntry {
return {
userId: context.actor.id,
action: command.id,
target: command.owner,
correlationId,
domain: command.owner,
...(reason === undefined ? {} : { reason }),
ipAddress,
};
}
function createRateLimitKey(
commandId: string,
context: HousekeepingCapabilityContext,
ipAddress = "0.0.0.0",
): string {
return `housekeeping-command:${context.actor.id}:${ipAddress}:${commandId}`;
}
function withCorrelation<T>(
result: HousekeepingResult<T>,
correlationId: string,
): HousekeepingResult<T> {
return { ...result, correlationId };
}
function outcomeFor(
result: HousekeepingResult<unknown>,
): "success" | "failure" | "denied" {
if (result.ok) return "success";
return result.error.code === "FORBIDDEN" ||
result.error.code === "VALIDATION" ||
result.error.code === "RATE_LIMITED"
? "denied"
: "failure";
}
async function finishWithAudit<T>(
writer: HousekeepingAuditWriter,
entry: AuditEntry,
outcome: "success" | "failure" | "denied",
result: HousekeepingResult<T>,
correlationId: string,
): Promise<HousekeepingResult<T>> {
try {
await writeOutcome(writer, entry, outcome);
return result;
} catch (error) {
return mapUnknownError(error, correlationId);
}
}
@@ -0,0 +1,50 @@
import { describe, expect, it } from "vitest";
import { z } from "zod";
import { anyCapability, ok } from "../contracts";
import {
getHousekeepingCommand,
type HousekeepingCommand,
registerHousekeepingCommand,
} from "./registry";
function command(
id: string,
owner: "people" | "system" = "people",
): HousekeepingCommand<{ id: number }, { id: number }> {
return {
id,
owner,
risk: "safe",
capability: anyCapability("admin.users.view"),
input: z.object({ id: z.number().int().positive() }),
requiresReason: false,
rateLimit: { attempts: 4, windowMs: 30_000 },
execute: async (context, input) => ok(input, context.correlationId),
};
}
describe("housekeeping command registry", () => {
it("returns the exact command registered under its global ID", () => {
const registered = command("people.registry.lookup");
registerHousekeepingCommand(registered);
expect(getHousekeepingCommand(registered.id)).toBe(registered);
});
it("rejects a duplicate global command ID before it can shadow its owner", () => {
registerHousekeepingCommand(command("people.registry.duplicate"));
expect(() =>
registerHousekeepingCommand(command("people.registry.duplicate")),
).toThrow("duplicate command id: people.registry.duplicate");
});
it("rejects a command whose namespace disagrees with its declared owner", () => {
expect(() =>
registerHousekeepingCommand(
command("people.registry.owner-mismatch", "system"),
),
).toThrow("command owner mismatch: people.registry.owner-mismatch");
});
});
@@ -0,0 +1,78 @@
import type { z } from "zod";
import {
HOUSEKEEPING_DOMAIN_IDS,
type HousekeepingDomainId,
} from "../../migration/types";
import type {
CapabilityRequirement,
HousekeepingCapabilityContext,
HousekeepingResult,
} from "../contracts";
export interface HousekeepingCommandContext {
capability: HousekeepingCapabilityContext;
correlationId: string;
ipAddress: string;
}
export interface HousekeepingCommand<I, O> {
id: string;
owner: HousekeepingDomainId;
risk: "safe" | "sensitive";
capability: CapabilityRequirement;
input: z.ZodType<I>;
requiresReason: boolean;
rateLimit: { attempts: number; windowMs: number };
execute(
context: HousekeepingCommandContext,
input: I,
): Promise<HousekeepingResult<O>>;
}
type RegisteredHousekeepingCommand = HousekeepingCommand<unknown, unknown>;
const approvedOwners = new Set<string>(HOUSEKEEPING_DOMAIN_IDS);
const commands = new Map<string, RegisteredHousekeepingCommand>();
export function registerHousekeepingCommand<I, O>(
command: HousekeepingCommand<I, O>,
): void {
validateCommand(command);
if (commands.has(command.id)) {
throw new Error(`duplicate command id: ${command.id}`);
}
commands.set(command.id, command as RegisteredHousekeepingCommand);
}
export function getHousekeepingCommand(
id: string,
): RegisteredHousekeepingCommand | undefined {
return commands.get(id);
}
function validateCommand<I, O>(command: HousekeepingCommand<I, O>): void {
if (typeof command.id !== "string" || !command.id.trim()) {
throw new Error("empty command id");
}
if (!approvedOwners.has(command.owner)) {
throw new Error(`unknown command owner: ${command.owner}`);
}
if (!command.id.startsWith(`${command.owner}.`)) {
throw new Error(`command owner mismatch: ${command.id}`);
}
if (
!command.input ||
typeof (command.input as { safeParse?: unknown }).safeParse !== "function"
) {
throw new Error(`command input schema missing: ${command.id}`);
}
if (
!Number.isInteger(command.rateLimit.attempts) ||
command.rateLimit.attempts <= 0 ||
!Number.isInteger(command.rateLimit.windowMs) ||
command.rateLimit.windowMs <= 0
) {
throw new Error(`invalid command rate limit: ${command.id}`);
}
}