Repository navigation
v0.8.0
feat(codex-ouronet): server-safe pre-bound headless Kadena KeyResolver (v0.8.0)
Adds createHeadlessKadenaResolver, exported from @ancientpantheon/codex/ouronet:
a pre-bound Kadena KeyResolver ({ getKeyPairByPublicKey, listCodexPubs }) that
headless Khronoton automatons (Pythia, Mnemosyne) drop straight into the engine's
resolver seam. A consumer supplies only loadSnapshot + getPassword thunks and
binds ZERO @StoaChain crypto itself — all seedType-aware derivation delegates to
Codex's one canonical createHeadlessCodexResolver.
This is Topic 1 of Pythia's khronoton-keyresolver-delegation: consumers had each
hand-rolled a KeyResolver that re-derived seeds koala-only, ignoring seedType, so
a chainweaver/eckowallet operator seed derived a different key and refused to
sign (a real live gas-payer failure; Mnemosyne carries the latent duplicate).
Delegating to Codex removes the reimplementation-per-consumer root cause.
- Extracted the real @StoaChain deps binding (REAL_STOA_DEPS,
buildExtendedForeignSigningKey, the shared HEADLESS instance, the core->ouronet
key-missing remap) out of the browser InternalCodexResolver.ts into a new
server-safe headlessKadenaDeps.ts that BOTH resolvers consume — one derivation
path, no duplication. InternalCodexResolver behaviour is unchanged (a pure
structural refactor; its own resolver-internal.test.ts stays green). - Fire-time: loadSnapshot + getPassword are re-invoked per call, never cached, so
a codex edit is picked up next tick and plaintext never outlives the call. - Wrong-key refusal guard re-added at the delegation boundary: if the codex
derives a different pubkey than requested (corrupt codex / wrong seedType tag),
it refuses to sign rather than return a mislabeled key (secret-free error). - Server-safe: importing from /ouronet loads no React/DOM (proven by a plain-Node
import of the built public dist).
Tests (real crypto end-to-end): koala + chainweaver + eckowallet SEED-derived
accounts each resolve and produce a VALID ed25519 signature (the exact non-koala
scenario that caused the live bug), chainweaver pure-import 128-hex WASM path,
foreign/pure, fire-time re-read counts, wrong-key refusal, and not-found counts.
codex-ouronet 67 files / 722 tests green; full workspace typecheck + build green.
codex-ouronet and codex both bump 0.7.0 -> 0.8.0 (MINOR, additive, no breaking
changes). Implements constructors/Pythia/docs/HANDOFF-codex-headless-kadena-resolver.md.
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com