Commit graph

3 commits

Author SHA1 Message Date
659ef5a62b
fix: repair platform resolution in the built bundles
All checks were successful
NYX Security Scan / nyx-scan (pull_request) Successful in 5m53s
The published package could not be used at all. `require('nomyo-js')`
succeeded, but constructing a client threw:

    Cannot find module './node'

Platform selection was done with a runtime require:

    const NodeSecureMemory = require('./node').NodeSecureMemory;

Rollup flattens every module into one file, so './node' and './browser'
no longer exist at runtime — and because the calls sit inside function
bodies, rollup left them as literal runtime requires rather than
resolving them. The failure was therefore deferred to first use: module
load and Object.keys() both looked fine, so nothing noticed. The
SecureCompletionClient constructor calls createSecureMemory() and
createHttpClient(), which made every client unconstructable.

Confirmed present at 057ff6c, this branch's merge base, so the npm
package has never worked.

Platform implementations are now injected by the entry points, which is
what src/node.ts and src/browser.ts always claimed to do (they merely
re-exported ./index). createSecureMemory/createHttpClient consult a
registered factory and throw a directive error if none was registered.
No require fallback is kept: leaving one would put an unresolvable
relative require back in the bundle, and bundlers resolve requires
statically, so webpack/vite would fail on a path that does not exist in
dist/. Jest registers the platform via tests/setup.ts instead.

This also keeps the Node HTTP client and the optional native addon out
of the browser bundle, which previously carried both.

Second defect found while verifying: dist/esm/index.mjs contained 13
require() calls (crypto, fs, path, jose, nomyo-native) that the source
loads lazily. `require` does not exist in ES module scope, so an ESM
consumer crashed with "require is not defined" as soon as one ran —
using keyDir for key persistence would have hit it on every Node
version. Node 24 masked the crypto case by having a global crypto. The
ESM output now carries a createRequire shim.

tests/integration/bundle.test.ts covers the artefact that actually
ships: both bundles construct a client, expose the API, resolve the
platform layer, keep Node-only modules out of the browser build, and the
ESM entry is imported and used by a real spawned Node process. Every
other suite runs against src/ through ts-jest, where these paths resolve
normally — which is precisely why this went unnoticed.

Verified end to end by installing the packed tarball into a clean
project: CommonJS and ESM both construct a client and run fs-backed key
generation on Node 18.19.1 and 24.18.0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 12:59:24 +02:00
111335d7ff
fix: correct package entry points and publish contents
Five packaging defects, all pre-existing:

1. dist/esm/index.js held ESM syntax while the package is not
   "type": "module", so Node classified it as CommonJS. It failed
   outright on Node 18 ("Unexpected token 'export'") and only worked on
   Node >= 22 because Node re-parses after guessing the module type,
   paying that cost on every import. Bundles now carry explicit
   extensions: .mjs for ES output, .cjs/.js for CommonJS. The browser
   build gained a real CommonJS output too — the exports map previously
   pointed the browser "require" condition at an ES module.
   The exports map now also leads with "types" and ends with a "default"
   fallback for resolvers matching neither "node" nor "browser".

2. files: ["native"] published the local build directory: a 94.6 kB
   Linux-x64 .node binary, a 148 kB object file and generated Makefiles.
   node-gyp-build checks build/Release before prebuilds, so every
   consumer on every platform would have found this machine's binary,
   skipped compiling, and failed to load it. It fails safe (native/
   index.js catches and returns null), but the addon could never work
   for anyone else. Narrowed to the four source files.

3. binding.gyp resolves node-addon-api at build time, but nothing
   declared it: it was a devDependency of the root, absent from
   native/package.json. The build only succeeded here because a dev
   install populates the root node_modules. Declared as a dependency of
   the native package, where it is actually needed.

4. No clean step, so stale output shipped — the tarball carried both
   dist/types/core/** and a dist/types/src/** tree left over from before
   rootDir was set. build now runs clean first.

5. test:browser ran `karma start` with no karma.conf.js anywhere in the
   repo, and tests/browser is an empty directory. Removed the script and
   the karma devDependency rather than leave a script that cannot run.

Verified: CommonJS require and ESM import both resolve on Node 18.19.1
and 24.18.0; TypeScript resolves types under both bundler and node16;
npm pack now produces 35 files / 103.8 kB with no build artefacts.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 12:39:09 +02:00
2495f1e6e8
fix: repair npm install and the rollup build
Some checks failed
NYX Security Scan / nyx-scan (pull_request) Failing after 5m58s
Three independent breakages, all present on main before this branch:

1. `npm ci` always exited non-zero. The root package.json carried
   "install": "node-gyp-build", but binding.gyp lives in native/, so the
   script ran in a directory with nothing to build:

     gyp: binding.gyp not found (cwd: <repo root>)

   native/package.json already declares that same install script in the
   right place, alongside its binding.gyp and "gypfile": true, so the
   root copy was a duplicate in the wrong package. Removing it also
   clears the now-inaccurate hasInstallScript flag from the lockfile.
   `npm ci` exits 0 again; the addon still builds from native/.

2. `npm run build` failed at the first step. @rollup/plugin-typescript
   requires tslib as a peer, and nothing depended on it directly — it was
   only present transitively as an optional dev dep, so a clean install
   could omit it entirely. Declared explicitly.

3. rollup.config.js used ESM syntax while package.json has no
   "type": "module", so Node parsed it as CommonJS and threw
   "Cannot use import statement outside a module". Node 24 recovers by
   reparsing (with a warning); Node 18 fails outright. Renamed to
   rollup.config.mjs, which is unambiguous on both. Setting
   "type": "module" instead would have broken jest.config.js, which is
   CommonJS.

Verified on Node 18.19.1 and Node 24.18.0: npm ci exits 0, npm run build
produces all three bundles plus declarations, and 76/76 tests pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 11:10:36 +02:00
Renamed from rollup.config.js (Browse further)