Skip to content

perf: optional extractor deps, incremental watch, and one TS-compat build - #72

Closed
martijn00 wants to merge 35 commits into
letstri:mainfrom
martijn00:perf/extractor-and-ci
Closed

perf: optional extractor deps, incremental watch, and one TS-compat build#72
martijn00 wants to merge 35 commits into
letstri:mainfrom
martijn00:perf/extractor-and-ci

Conversation

@martijn00

Copy link
Copy Markdown
Contributor

Summary

  • stacks on #71; review the last commit(s) once fix: rehydrate Svelte on state change and run UI checks through the instance #71 merges
  • chokidar, oxc-parser, and tinyglobby are optional peers (not hard dependencies) because npm always installs optionalDependencies; UI-only installs no longer pull extractor natives
  • watch reuses a per-file mtime/size parse cache, invalidates dirty paths, and --force rescans
  • TypeScript compatibility CI builds permix/dist once and reuses it; local type-check:compat:* skips rebuild when dist already exists
  • raise the hono peer floor to >=4.12.25 (does not replace #65)

Test plan

  • pnpm exec vitest run src/extractor
  • pnpm test
  • pnpm run check-types
  • pnpm --filter permix size:compare

Checklist

  • docs and permix/skills/ note the optional extractor peers
  • extractor and next-config bundle budgets lowered after natives left the graph

Made with Cursor

martijn00 and others added 30 commits August 27, 2026 19:31
Develop the library on TypeScript 7 while keeping the consumer peer at 5.9–7, and pin shared toolchain versions through a strict pnpm catalog so CI and local installs stay aligned.

Co-authored-by: Cursor <cursoragent@cursor.com>
Give each factory its own provider/hook/Check bindings so nested policies do not share state, and hydrate dehydrated rules on the first client render without mutating during render.

Co-authored-by: Cursor <cursoragent@cursor.com>
Cache one initialized instance per RSC request so concurrent server callers share setup, and keep layouts synchronous with permission work behind Suspense for Cache Components.

Co-authored-by: Cursor <cursoragent@cursor.com>
Subscribe to setup/ready during render instead of after an effect so dehydrated booleans and already-initialized rules are visible on the first paint.

Co-authored-by: Cursor <cursoragent@cursor.com>
Toolchain skills from skills.sh fail format check and are not project source.

Co-authored-by: Cursor <cursoragent@cursor.com>
Oxfmt rejected the barrel and type-test files, and pinning React 18 in the catalog conflicts with docs/fumadocs React 19 peers.

Co-authored-by: Cursor <cursoragent@cursor.com>
Oxfmt requires a single trailing newline after the merge from the React factory branch.

Co-authored-by: Cursor <cursoragent@cursor.com>
Reconstruct published npm history, show it on the docs site, and wire conventional-commit releases.

Co-authored-by: Cursor <cursoragent@cursor.com>
Upgrade Fumadocs to 16.15 with the Base UI alias.

Ignore .agents and .claude so CI format check skips third-party skill files.

Co-authored-by: Cursor <cursoragent@cursor.com>
pnpm 11 rejects packages newer than one day in frozen CI installs.

Co-authored-by: Cursor <cursoragent@cursor.com>
Wire Permix into Nest via APP_GUARD so each request gets its own instance, then enforce @check on handlers without tying the API to Express middleware. Closes letstri#11.

Co-authored-by: Cursor <cursoragent@cursor.com>
Store one Permix instance per Nitro event so Nuxt server routes and Vue SSR share rules without leaking state across requests.

Co-authored-by: Cursor <cursoragent@cursor.com>
Store a per-request Permix instance on Astro locals so middleware, endpoints, and pages can share rules without tying UI islands to a new client adapter.

Co-authored-by: Cursor <cursoragent@cursor.com>
React Router 7 (including Remix) needs a per-request instance on middleware context so loaders can dehydrate into permix/react.

Co-authored-by: Cursor <cursoragent@cursor.com>
Reuse existing Zod, Valibot, or ArkType schemas on action specs and via
permix/standard-schema so ReBAC callbacks stay typed without duplicate
interfaces. check() still does not parse data at runtime.

Co-authored-by: Cursor <cursoragent@cursor.com>
Parse check() data with the entity schema when validate is deny or throw, and lock Zod, Valibot, ArkType, and Effect Schema behind regression tests so those integrations stay working.

Co-authored-by: Cursor <cursoragent@cursor.com>
…talog-extraction

Co-authored-by: Cursor <cursoragent@cursor.com>
…talog-extraction

Co-authored-by: Cursor <cursoragent@cursor.com>
…talog-extraction

Co-authored-by: Cursor <cursoragent@cursor.com>
…talog-extraction

Co-authored-by: Cursor <cursoragent@cursor.com>
…talog-extraction

Co-authored-by: Cursor <cursoragent@cursor.com>
…talog-extraction

Co-authored-by: Cursor <cursoragent@cursor.com>
Avoid passing undefined React Router params. Narrow the generated Svelte
component at its factory boundary so TypeScript 7 checks remain valid.

Co-authored-by: Cursor <cursoragent@cursor.com>
Derive typed definitions and metadata from static permission markers so application usage becomes
the catalog source of truth. Include CLI, watch and check workflows, Next.js integration, typed
payload overlays, provider coverage validation, and consumer guidance.

Co-authored-by: Cursor <cursoragent@cursor.com>
Measure every public entry in CI and preserve tree-shaking boundaries.
Avoid rerendering Check when its permission result is unchanged.

Co-authored-by: Cursor <cursoragent@cursor.com>
…in CI

Hydrate and check treated inherited Object.prototype names as allowing
rules, and Fastify/Elysia could fall through after a custom deny handler.
Freeze a null-prototype copy of rules so caller mutation cannot change
authorization, and gate PRs on the full Vitest suite.

Co-authored-by: Cursor <cursoragent@cursor.com>
Null-prototype frozen rules and Object.hasOwn lookups add ~550 bytes to
the core graph; raise ceilings with the usual 12% headroom and keep
delta caps so later PRs still cannot grow unchecked.

Co-authored-by: Cursor <cursoragent@cursor.com>
@vercel

vercel Bot commented Aug 28, 2026

Copy link
Copy Markdown

@martijn00 is attempting to deploy a commit to the letstri Team on Vercel.

A member of the Team first needs to authorize it.

Co-authored-by: Cursor <cursoragent@cursor.com>
@martijn00
martijn00 force-pushed the perf/extractor-and-ci branch from 339d557 to e831db1 Compare August 28, 2026 23:51
martijn00 and others added 3 commits August 29, 2026 01:55
Co-authored-by: Cursor <cursoragent@cursor.com>
…nstance

UI check() now goes through the live instance once rules exist so hooks
and Standard Schema validate run, Svelte hydrate follows state, and Vue
Check caches a computed boolean. Document that core setup() is not
request-safe.

Co-authored-by: Cursor <cursoragent@cursor.com>
…uild

Move chokidar, oxc-parser, and tinyglobby to optional peers so UI-only
installs skip native parser binaries. Cache per-file parses during
watch, and build dist once before the TypeScript compatibility matrix.

Co-authored-by: Cursor <cursoragent@cursor.com>
@martijn00
martijn00 force-pushed the perf/extractor-and-ci branch from e831db1 to 1fb1c2b Compare August 28, 2026 23:56
@letstri

letstri commented Sep 6, 2026

Copy link
Copy Markdown
Owner

Closing: toolchain/CI churn that we don't want to take on, and it's stacked on PRs that are being closed.

@letstri letstri closed this Sep 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants