返回 X 名人动态

Guillermo Rauch 介绍 TypeScript 安全 API 工具 gdp-ts

中文全文 · AI 翻译

介绍 gdp-ts:面向 TypeScript 的 Ghosts of Departed Proofs。

gdp-ts 集库、代码检查器和 AI 技能于一体,用于更安全的 API 设计。在这套约定下,敏感函数要求调用方提供已执行授权检查的“证明”。

类型检查器在编译时验证这些证明,防止团队和代理交付带有灾难性安全漏洞或其他严重缺陷的代码。

虽然这些模式已经存在很久,尤其是在 Haskell 等生态中,但①人工代码审查,以及②认知与语法开销,让这些方案一直相对小众。

现在形势逆转了。代理编写代码的速度已经超过我们的审查能力,而那些会让我们烦躁的严格约束和紧密反馈循环,却恰好让代理如鱼得水。从 Rust 的兴起、借用检查器到代码美学之争,都能看到这一点。

README 和示例模拟了 Vercel API 产品的一项真实约束:修改项目密码,必须证明调用者具备特定角色和特定权限。感谢 Matt Noonan 和 Ollie Charles 在该领域的研究。

https://github.com/rauchg/gdp-ts

对照原文

Introducing gdp-ts: Ghosts of Departed Proofs for TypeScript. gdp-ts is a library, linter and AI skill for safer API design. Under this contract, sensitive functions require 'proofs' that the caller performed an authorization check. The typechecker verifies these proofs at compile time, preventing your team and agents from shipping catastrophic security (and other kinds of) bugs. While these patterns have existed for quite some time, especially in ecosystems like Haskell, ① human code review and ② cognitive and syntactic overhead made these solutions niche. The situation is now inverted. Agents are writing more code than we can review, and they *thrive* in tight loops with hard constraints that would frustrate us. We see this with the rise of Rust, borrow checker, code aesthetics debate and all. The README and examples model a real-world Vercel API product constraint: changing the password on a Project requires a proof of a certain role + a certain entitlement. Thanks to Matt Noonan and Ollie Charles for their research in this space. https://t.co/eRWdiMvQ2V

老杨AI实操

微信扫一扫,添加好友

老杨AI实操的微信好友二维码

手机可长按保存图片,再到微信中识别二维码

保存二维码