2026-01-17 12:02:08 +01:00
|
|
|
{
|
|
|
|
|
"name": "nomyo-js",
|
feat: align timeout, error types and docs with the Python SDK
Completes the parity work (step 4).
Request timeout now defaults to 900 s, matching Python, instead of 60 s.
Encrypted inference cannot stream, so an entire completion arrives in one
response; a long generation on a busy backend legitimately takes minutes
and was timing out here while succeeding in the Python client.
Error types now distinguish malformed data from integrity failures.
Python raises ValueError for a bad package, a non-200 or unparseable
/pki/public_key, and plaintext that will not parse, reserving
SecurityError for crypto failures. This port wrapped nearly all of it in
SecurityError — so a server sending malformed JSON was reported as an
authentication failure, pointing debugging in exactly the wrong
direction. Malformed data is now a plain Error (the JS equivalent of
ValueError), carried past the deliberately opaque catch-all by a symbol
marker rather than a new exported class. Genuine crypto failures still
report a single vague message so they cannot serve as a decryption
oracle.
Also adds the missing guard Python has: decrypting without a private key
now says so, instead of failing later and being reported as an integrity
failure.
doc/attestation.md ports the Python attestation guide to the JS API, and
documents the two deliberate divergences: no verify_ssl escape hatch, and
jose injection instead of a runtime dynamic import.
Version 0.1.0 -> 0.3.0 to match the Python client's feature level, now
that the two are at parity.
Not ported: Python's warning when secure_memory=True but the SecureMemory
module is unavailable. There is no JS equivalent — zeroing is always
available, and the weaker case (mlock unavailable) is already reported
honestly by getProtectionInfo().
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 12:17:52 +02:00
|
|
|
"version": "0.3.0",
|
2026-01-17 12:02:08 +01:00
|
|
|
"description": "OpenAI-compatible secure chat client with end-to-end encryption",
|
|
|
|
|
"main": "dist/node/index.js",
|
|
|
|
|
"browser": "dist/browser/index.js",
|
|
|
|
|
"module": "dist/esm/index.js",
|
|
|
|
|
"types": "dist/types/index.d.ts",
|
|
|
|
|
"exports": {
|
|
|
|
|
".": {
|
|
|
|
|
"node": {
|
|
|
|
|
"require": "./dist/node/index.js",
|
|
|
|
|
"import": "./dist/esm/index.js"
|
|
|
|
|
},
|
|
|
|
|
"browser": {
|
|
|
|
|
"import": "./dist/browser/index.js",
|
|
|
|
|
"require": "./dist/browser/index.js"
|
|
|
|
|
},
|
|
|
|
|
"types": "./dist/types/index.d.ts"
|
|
|
|
|
}
|
|
|
|
|
},
|
|
|
|
|
"files": [
|
|
|
|
|
"dist",
|
|
|
|
|
"native",
|
|
|
|
|
"README.md",
|
|
|
|
|
"LICENSE"
|
|
|
|
|
],
|
|
|
|
|
"scripts": {
|
|
|
|
|
"build": "npm run build:node && npm run build:browser && npm run build:types",
|
|
|
|
|
"build:node": "rollup -c --environment TARGET:node",
|
|
|
|
|
"build:browser": "rollup -c --environment TARGET:browser",
|
|
|
|
|
"build:types": "tsc --emitDeclarationOnly",
|
|
|
|
|
"test": "jest",
|
|
|
|
|
"test:browser": "karma start",
|
|
|
|
|
"prepublishOnly": "npm run build && npm test"
|
|
|
|
|
},
|
|
|
|
|
"keywords": [
|
|
|
|
|
"openai",
|
|
|
|
|
"encryption",
|
|
|
|
|
"secure",
|
|
|
|
|
"chat",
|
|
|
|
|
"e2e",
|
|
|
|
|
"privacy",
|
|
|
|
|
"nomyo"
|
|
|
|
|
],
|
|
|
|
|
"author": "",
|
|
|
|
|
"license": "Apache-2.0",
|
2026-03-04 11:30:44 +01:00
|
|
|
"engines": {
|
2026-06-26 12:36:50 +00:00
|
|
|
"node": ">=22.22.2"
|
2026-03-04 11:30:44 +01:00
|
|
|
},
|
2026-01-17 12:02:08 +01:00
|
|
|
"devDependencies": {
|
2026-05-10 10:44:53 +00:00
|
|
|
"@rollup/plugin-commonjs": "^29.0.0",
|
2026-05-10 10:51:23 +00:00
|
|
|
"@rollup/plugin-node-resolve": "^16.0.0",
|
2026-05-10 10:45:08 +00:00
|
|
|
"@rollup/plugin-typescript": "^12.0.0",
|
2026-05-10 11:00:35 +00:00
|
|
|
"@types/jest": "^30.0.0",
|
2026-05-10 10:45:15 +00:00
|
|
|
"@types/node": "^24.0.0",
|
2026-05-10 11:00:35 +00:00
|
|
|
"jest": "^30.0.0",
|
2026-01-17 12:02:08 +01:00
|
|
|
"karma": "^6.4.0",
|
2026-03-04 11:30:44 +01:00
|
|
|
"node-addon-api": "^8.6.0",
|
2026-06-12 13:28:30 +00:00
|
|
|
"node-gyp": "^13.0.0",
|
2026-03-04 11:30:44 +01:00
|
|
|
"node-gyp-build": "^4.8.0",
|
|
|
|
|
"rollup": "^4.0.0",
|
|
|
|
|
"ts-jest": "^29.4.6",
|
fix: repair npm install and the rollup build
Three independent breakages, all present on main before this branch:
1. `npm ci` always exited non-zero. The root package.json carried
"install": "node-gyp-build", but binding.gyp lives in native/, so the
script ran in a directory with nothing to build:
gyp: binding.gyp not found (cwd: <repo root>)
native/package.json already declares that same install script in the
right place, alongside its binding.gyp and "gypfile": true, so the
root copy was a duplicate in the wrong package. Removing it also
clears the now-inaccurate hasInstallScript flag from the lockfile.
`npm ci` exits 0 again; the addon still builds from native/.
2. `npm run build` failed at the first step. @rollup/plugin-typescript
requires tslib as a peer, and nothing depended on it directly — it was
only present transitively as an optional dev dep, so a clean install
could omit it entirely. Declared explicitly.
3. rollup.config.js used ESM syntax while package.json has no
"type": "module", so Node parsed it as CommonJS and threw
"Cannot use import statement outside a module". Node 24 recovers by
reparsing (with a warning); Node 18 fails outright. Renamed to
rollup.config.mjs, which is unambiguous on both. Setting
"type": "module" instead would have broken jest.config.js, which is
CommonJS.
Verified on Node 18.19.1 and Node 24.18.0: npm ci exits 0, npm run build
produces all three bundles plus declarations, and 76/76 tests pass.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 11:10:36 +02:00
|
|
|
"tslib": "^2.8.1",
|
2026-05-10 10:45:29 +00:00
|
|
|
"typescript": "^6.0.0"
|
2026-01-17 12:02:08 +01:00
|
|
|
},
|
|
|
|
|
"optionalDependencies": {
|
|
|
|
|
"nomyo-native": "file:./native"
|
|
|
|
|
}
|
2026-03-04 11:30:44 +01:00
|
|
|
}
|