feat(resource-id): implement deterministic resource identifier codec with namespace isolation - #408
Merged
Lakes41 merged 1 commit intoAug 31, 2026
Conversation
…with namespace isolation - Add ResourceIdentifier interface with namespace and segments - Implement parseResourceId with comprehensive validation - Implement formatResourceId producing canonical representation - Add percent-encoding for reserved delimiters (: / %) - Validate namespace syntax (alphanumeric, underscore, hyphen) - Reject empty segments and path traversal patterns - Impose configurable length limits for security - Support round-trip parse/format consistency - Add equality and lexicographic comparison helpers - Include 38 comprehensive unit tests covering Unicode, encoding, edge cases - All validation requirements per issue Adamantine-guild#388 Closes Adamantine-guild#388
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Implements a deterministic resource identifier codec with namespace isolation for GuildPass access control systems.
Changes
@guildpass/resource-idwith complete TypeScript implementationResourceIdentifierwith namespace and segments structureparseResourceIdwith comprehensive validationformatResourceIdproducing canonical representation:,/,%).,..,\)Implementation Details
The codec uses
:as namespace delimiter and/as segment delimiter, with percent-encoding for reserved characters. All validation is deterministic and security-focused:Testing
pnpm typecheckpassespnpm buildpassesAcceptance Criteria Met
✅ Valid identifiers parse into expected namespace and segments
✅ Formatting produces canonical representation
✅ Parse/format round trips succeed
✅ Empty namespaces and segments rejected
✅ Reserved delimiter handling explicit and tested
✅ Oversized identifiers rejected
✅ Malformed escaping/encoding rejected safely
✅ Canonically equivalent identifiers compare equally
✅ Comprehensive unit tests cover all edge cases
✅ Independent implementation (no external dependencies)
Closes #388