jeswr / jeswr/solid-a2a

Sign-off: merge refactor/reviewability (68b0 — API snapshot + handshake/intent decomposition, characterization byte-identical, roborev clean)

Open
#4 0 comments 0 reactions 1 assignee Claimed by @jeswr View on GitHub
Dominant language
TypeScript
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Branch `refactor/reviewability` @ `5a34d56` (pushed) is ready to merge to `main`. The handshake verification path (no-silent-downgrade, spoofing/ambiguity rejection) is security-relevant, so this joins the sign-off queue (same policy as solid-odrl#4).

## Evidence bundle
- **5 commits off `e3fcbd8`**, all behavior-preserving: api-extractor cornerstone (committed `etc/solid-a2a.api.md`, `api:check` drift gate, `ae-forgotten-export=error`), `handshakeFromRdf` complexity 21→<15 and `projectIntent` 18→<15 (decomposed into named fail-closed steps), +1 semver-minor type export (`BuildShapeOptions`, already implicitly public).
- **The pre-existing 41-snapshot byte-exact characterization golden-master is UNCHANGED** — RDF output, content hashes, and JSON-LD proven identical across every commit. 171/171 tests green.
- **Deliberate non-changes**: the custom canonicalizer stays (swapping to `rdf-canonize` would re-key every published content hash — a semver migration, not a refactor); `constantTimeEquals` kept (trivial+total); essential security branches preserved verbatim.
- roborev (codex): 4× "No issues found"; one Medium ("lockfile not updated") is a confirmed false positive — the commit contains the 498-line lockfile diff and a keyless `npm ci` installs and runs `api:check` (refuted by execution).
- Gate: lint / typecheck / 171 tests / `check:dist` / `api:check` / `check:lockfile-transport` / keyless `npm ci` all green.
- Follow-ups recorded, not blocking: internal vocab-export trim (your call), the future `rdf-canonize` fidelity migration, a small knip config.

**Ask:** merge `refactor/reviewability` → `main` (fast-forward), or comment and I'll adjust.

🤖 PSS agent — @jeswr's agent for `prod-solid-server` / the Solid app+Pod-Manager suite

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.