feat/mosaic-as-m4a
main
Phase M4a of the Matrix agent-comms roadmap (mosaicstack/agent-comms#9, design doc: agent-comms docs/design/M4-MOSAIC-AS.md). New zero-dep package @mosaicstack/appservice: AS transactions handling, virtual-user intent (@agent-* namespace), Synapse registration builder, bridge DTOs. 14 vitest tests; build/lint/typecheck/format green. Security review applied: timing-safe hs_token compare, YAML injection hardening, uuid txn ids, DTO slug validation. Next phases: apps/appservice daemon host + Synapse registration rollout (M4a deploy), daemon bridge integration (M4b).
First phase of mosaic-as per agent-comms docs/design/M4-MOSAIC-AS.md: - TransactionHandler: AS transactions endpoint logic with timing-safe hs_token verification (Bearer + legacy access_token), bounded txnId dedupe (documented at-least-once limitation), handler error isolation - AppserviceIntent: virtual user registration (m.login.application_service), user_id impersonation, invite-then-join fallback, thread-aware sends (m.thread + is_falling_back), typing, display names, uuid txn ids - Registration builder + hardened YAML serializer (control-char rejection, quote escaping) for the Synapse mosaic-as.yaml - bridge.dto.ts validators for the agent-comms daemon bridge API Zero runtime deps; strict ESM/NodeNext; 14 vitest tests. Co-Authored-By: Claude Fable 5 <[email protected]>
No dependencies set.
The note is not visible to the blocked user.
Phase M4a of the Matrix agent-comms roadmap (mosaicstack/agent-comms#9, design doc: agent-comms docs/design/M4-MOSAIC-AS.md). New zero-dep package @mosaicstack/appservice: AS transactions handling, virtual-user intent (@agent-* namespace), Synapse registration builder, bridge DTOs. 14 vitest tests; build/lint/typecheck/format green. Security review applied: timing-safe hs_token compare, YAML injection hardening, uuid txn ids, DTO slug validation. Next phases: apps/appservice daemon host + Synapse registration rollout (M4a deploy), daemon bridge integration (M4b).