Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
e2116f1
Project import generated by Copybara.
Sep 20, 2026
b6bfa52
Project import generated by Copybara.
Sep 20, 2026
b57c52f
Project import generated by Copybara.
Sep 20, 2026
84196ef
Project import generated by Copybara.
Sep 20, 2026
fd8f5f2
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 20, 2026
50b8030
Project import generated by Copybara.
Sep 20, 2026
0b33a40
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 20, 2026
0909f49
chore: project deixic-node from Mono a2e8b231b208
Sep 20, 2026
7f83bc2
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 20, 2026
52af6bb
chore: project deixic-node from Mono cc1e1c0a4251
Sep 20, 2026
4afc25f
chore: project deixic-node from Mono 9b559bc70e7d
Sep 21, 2026
1b8e1d5
chore: project deixic-node from Mono 78799bd5ae75
Sep 21, 2026
bf937ed
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 21, 2026
56a0303
chore: project deixic-node from Mono 9a003786d767
Sep 21, 2026
e1d7f6b
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 21, 2026
7104709
chore: project deixic-node from Mono 511bd2305f5a
Sep 21, 2026
8007e8f
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 21, 2026
66f5141
chore: project deixic-node from Mono ad7b9df0b712
Sep 21, 2026
739018e
chore: project deixic-node from Mono 3a95acea6719
Sep 21, 2026
3265b56
chore: project deixic-node from Mono c16f3515c56a
Sep 21, 2026
3f717b5
chore: project deixic-node from Mono 4ab4845398fd
Sep 21, 2026
1a9ff5f
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 22, 2026
44a3b57
chore: project deixic-node from Mono 43ad52f7bcc9
Sep 22, 2026
581d89c
chore: project deixic-node from Mono 2df44a8283c0
Sep 22, 2026
1dafa3d
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 22, 2026
aa671c6
chore: project deixic-node from Mono f6e0aa99e756
Sep 22, 2026
3d4113e
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 22, 2026
28794da
chore: project deixic-node from Mono 3457dcec675e
Sep 22, 2026
6edfd15
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 22, 2026
76325ea
chore: project deixic-node from Mono 2102d45bdf4c
Sep 22, 2026
5c0d888
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 23, 2026
00a9176
chore: project deixic-node from Mono 0135ea0655c8
Sep 23, 2026
61430dd
Merge remote-tracking branch 'origin/main' into sync/mono-projection
github-actions[bot] Sep 23, 2026
8dd3303
chore: project deixic-node from Mono 7f322bbd03a5
Sep 23, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .repository-projection.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,11 +3,11 @@
"projection": "deixic-node",
"projectionSchemaVersion": 1,
"sourceRepository": "dx-corp/mono",
"sourceSha": "0135ea0655c81b1b2a8e7fb5e4fb00d827607b35",
"sourceSha": "7f322bbd03a590ed5a478b12303369ea8d48c00a",
"destinationRepository": "dx-corp/deixic-node",
"priorProjectedBase": "814b96ca0a16ea04f7d94544389238725fdfdddb",
"priorProjectedBase": "b9802c8dca99bfd256d5f9fc1e21f728af26d27a",
"definitionDigest": "6c8bda5a9e80c50ccdc2d79d85f61b7f2373eb695dcc86f51f6240901cdf3c28",
"toolDigest": "f58d71f023a4f0a27d77cb96dcc5348a40816d0b",
"contentDigest": "1efaa60d2594ebac6aec18f14a42f5f40be871b97b20f84dbca8addea2333b29",
"toolDigest": "898e8657d9153a2a51d7c283bf83bb3350b5d1e6",
"contentDigest": "1959422422c9ca7d87cb6bff7771da6a23e6effa8acea4977dd8e7bb32579316",
"publicationEligible": true
}
175 changes: 174 additions & 1 deletion gen/ts/console/v1/console_pb.ts

Large diffs are not rendered by default.

20 changes: 18 additions & 2 deletions gen/ts/deixic/v1/deixic_pb.ts

Large diffs are not rendered by default.

6 changes: 4 additions & 2 deletions sdk/deixic/typescript/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,8 +65,10 @@ the internal `DEX-ACTION-ASSURANCE` control; mapping that control to an
external framework requires a separately reviewed mapping. Denied actions are `NOT_APPLICABLE`;
executions without a confirmed succeeded state are `INDETERMINATE`. It includes a
digest of the exact Tool Execution returned by the owner and declares coverage
of one requested record. This is a live read; store the result in your own
system if you need to retain that observation. The current profile reports
of one requested record. This is a live read. To retain a server-owned
snapshot, call `deixic.compliance.record()` with the same subject and an
`idempotencyKey`, then retrieve its `record.id` with `deixic.compliance.get()`.
Repeating the key returns the first accepted snapshot. The current profile reports
the independent Audit receipt as indeterminate because Tool Executor has no
general Audit sink. Do not treat the result as proof of an external state
change or of every action in a time window.
Expand Down
5 changes: 5 additions & 0 deletions sdk/deixic/typescript/src/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -135,6 +135,8 @@ export type {
export type {
MaestroGetReceiptInput as GetReceiptInput,
MaestroAssessComplianceInput as AssessComplianceInput,
MaestroRecordComplianceInput as RecordComplianceInput,
MaestroGetComplianceInput as GetComplianceInput,
MaestroGetThreadInput as GetThreadInput,
MaestroInterruptThreadInput as InterruptThreadInput,
MaestroListThreadEventsInput as ListThreadEventsInput,
Expand All @@ -157,8 +159,11 @@ export {

export type {
AssessComplianceSubjectResponse,
ComplianceAssessmentRecord,
ComplianceSubjectAssessment,
ComplianceRequirementFinding,
GetComplianceAssessmentResponse,
RecordComplianceAssessmentResponse,
GetOperatingReceiptResponse,
GetOperatingThreadResponse,
InterruptOperatingThreadResponse,
Expand Down
25 changes: 25 additions & 0 deletions sdk/deixic/typescript/test/client.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ import test from "node:test";
import { create } from "@bufbuild/protobuf";
import {
AssessComplianceSubjectResponseSchema,
GetComplianceAssessmentResponseSchema,
RecordComplianceAssessmentResponseSchema,
GetOperatingThreadResponseSchema,
SubmitOperatingMessageResponseSchema,
} from "../dist/gen/ts/console/v1/console_pb.js";
Expand Down Expand Up @@ -60,6 +62,29 @@ test("compliance assessments use the fixed tenant and a typed Deixic RPC", async
assert.equal(transport.calls[0].input.subjectId, "execution-1");
});

test("compliance records bind tenant and replay key through typed RPCs", async () => {
const transport = new RecordingTransport(({ method }) => create(
method.name === "RecordComplianceAssessment"
? RecordComplianceAssessmentResponseSchema : GetComplianceAssessmentResponseSchema,
{ record: { id: "ca_1" } },
));
const deixic = createDeixicClient({
organizationId: "org-a", workspaceId: "workspace-a", apiKey: "sdk-test-key", transport,
});
await deixic.compliance.record({
profileId: "dex-production-action-assurance/v1", subjectKind: "tool_execution",
subjectId: "execution-1", idempotencyKey: "snapshot-1",
});
await deixic.compliance.get({ recordId: "ca_1" });
assert.deepEqual(transport.calls.map(({ method }) => method.name), [
"RecordComplianceAssessment", "GetComplianceAssessment",
]);
assert.equal(transport.calls[0].input.organizationId, "org-a");
assert.equal(transport.calls[0].input.workspaceId, "workspace-a");
assert.equal(transport.calls[0].input.idempotencyKey, "snapshot-1");
assert.equal(transport.calls[1].input.recordId, "ca_1");
});

test("public client fixes tenant scope and sends an API key as a bearer", async () => {
const transport = new RecordingTransport(() => create(SubmitOperatingMessageResponseSchema, {
replayCursor: 8n,
Expand Down
40 changes: 40 additions & 0 deletions sdk/maestro/typescript/src/client.ts
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@ import { createClient, type Transport } from "@connectrpc/connect";
import { createConnectTransport } from "@connectrpc/connect-web";
import {
AssessComplianceSubjectRequestSchema,
GetComplianceAssessmentRequestSchema,
RecordComplianceAssessmentRequestSchema,
CodingAcceptanceContractSchema,
ConsoleQuerySchema,
GetOperatingReceiptRequestSchema,
Expand All @@ -33,6 +35,8 @@ import {
WatchOperatingThreadResponseSchema,
type GetOperatingReceiptResponse,
type AssessComplianceSubjectResponse,
type GetComplianceAssessmentResponse,
type RecordComplianceAssessmentResponse,
type GetOperatingThreadResponse,
type InterruptOperatingThreadResponse,
type ListOperatingThreadEventsResponse,
Expand Down Expand Up @@ -178,6 +182,15 @@ export interface MaestroAssessComplianceInput {
signal?: AbortSignal;
}

export interface MaestroRecordComplianceInput extends MaestroAssessComplianceInput {
idempotencyKey: string;
}

export interface MaestroGetComplianceInput {
recordId: string;
signal?: AbortSignal;
}

export interface MaestroResolveReceiptInput {
receiptId: string;
/** Exact action object returned in receipt.allowedActions. */
Expand All @@ -194,6 +207,8 @@ export interface MaestroProductClient {
readonly scope: Readonly<MaestroProductScope>;
compliance: {
assess(input: MaestroAssessComplianceInput): Promise<AssessComplianceSubjectResponse>;
record(input: MaestroRecordComplianceInput): Promise<RecordComplianceAssessmentResponse>;
get(input: MaestroGetComplianceInput): Promise<GetComplianceAssessmentResponse>;
};
threads: {
get(input: MaestroGetThreadInput): Promise<GetOperatingThreadResponse>;
Expand Down Expand Up @@ -398,6 +413,31 @@ export function createMaestroProductClient(options: MaestroProductClientOptions)
signal: input.signal,
}));
},
record(input) {
const request = snapshotRequest(RecordComplianceAssessmentRequestSchema, {
organizationId: scope.organizationId,
workspaceId: scope.workspaceId,
profileId: input.profileId,
subjectKind: input.subjectKind,
subjectId: required(input.subjectId, "subjectId"),
idempotencyKey: required(input.idempotencyKey, "idempotencyKey"),
});
return unary((requestHeaders) => client.recordComplianceAssessment(request, {
headers: requestHeaders,
signal: input.signal,
}));
},
get(input) {
const request = snapshotRequest(GetComplianceAssessmentRequestSchema, {
organizationId: scope.organizationId,
workspaceId: scope.workspaceId,
recordId: required(input.recordId, "recordId"),
});
return unary((requestHeaders) => client.getComplianceAssessment(request, {
headers: requestHeaders,
signal: input.signal,
}));
},
},
threads: {
get(input) {
Expand Down