Skip to program ledger

Living Program Ledger

Frauthy/Project Management

v37 · 2026-07-28

Repository dossier

market

The marketplace — listings, tiers, domain registration

At risk
Branch
master
Commit
5c02958d9e8f7dfde04e4145b7722792f7602cad
Worktree
Clean
SDK
@frauthy/market-ui 1.1.0-next.0 source; 1.0.0-next.0 published and Brand-admitted

stack

Bun · Hono · Astro + Solid web

ci

green (exact-head Market CI run 29755782538: backend, UI/web, container health, coverage, and reusable dispatch caller)

deploy

Marketplace links use the canonical Site origin while image publication and runtime rollout remain gated; no image or provider resource was published

coverage

63.19% remote measurement; 61.19% upward-only floor; 80% target

What it is. The marketplace — publish and discover modules, schemas, and identity domains, with the four visibility tiers (public · private · permissioned · unlisted) each resolving the same listing#discover permission through Frauthy’s own ReBAC graph, plus the domain-registration UX.

What’s proven. The tier model is real: full Zanzibar semantics in the MemStore (direct, wildcard, arrow), a genuine SpiceDB HTTP adapter, and every listing route gated by actual check()/lookupResources() calls. The registrar’s verify state machine and ~2,900 lines of tests hold up.

Where it falls short. The front door is open: authentication is a trusted X-User-Id header — no OIDC, no sessions, nothing. The default context is in-memory (the finished PgRepo is only exercised by a live test), domain verification is a StubVerifier that always answers yes, module “distribution” returns a hardcoded S3 URL string with no storage behind it, the web UI renders hardcoded sample data, and the service emits zero traces.

The plan. market/specs/GAP-CLOSURE-2026-07-12.md (MKT-1 … MKT-11): authentication first — and it’s the flagship internal dogfood, frauthy.session(req) via @frauthy/sdk-ts protecting Frauthy’s own marketplace — then Postgres wiring, real verifiers (well-known / DNS TXT / connect-OIDC), artifact storage with a local-filesystem dev driver, OTLP, and the live-API web UI.

full spec: market/specs/GAP-CLOSURE-2026-07-12.md · port :41016