Skip to content

v0.1.1

Latest

Choose a tag to compare

@Latestinssan Latestinssan released this 22 Sep 16:04
· 8 commits to main since this release

RTQ Release v0.1.1 — Updated READMEs, npm keywords, and mobile enhancements

GitHub All Releases
npm version
License

RTQ continues its zero‑third‑party‑dependency approach, now with fully‑documented READMEs and curated npm keywords for every @rtq/* package. The mobile package has been renamed to Rtq, now includes native OS screen‑lock (Android biometric verification with device‑credential fallback, iOS Face/Touch ID support), and ships a placeholder unsigned .ipa asset.


📦 Published npm Monorepo Packages (@rtq/* v0.1.1)

Package Version Link Role
@rtq/security 0.1.1 npm Unified pipeline façade (createRTQ)
@rtq/cli 0.1.1 npm Security CLI (capabilities, policy, sandbox, audit)
@rtq/mcp 0.1.1 npm Business‑grade MCP gateway
@rtq/core 0.1.1 npm Capability registry, ticket store, schema validation
@rtq/crypto 0.1.1 npm Canonical JSON, SHA‑256, Ed25519 signing
@rtq/sandbox 0.1.1 npm macOS Seatbelt, Linux bubblewrap, Windows AppContainer
@rtq/approval 0.1.1 npm QR‑based approval strategies
@rtq/mobile 0.1.1 npm Rtq – mobile approval host transport & pairing server
@rtq/risk 0.1.1 npm Authoritative risk engine (raise‑only)
@rtq/policy 0.1.1 npm Declarative default‑deny rule evaluator
@rtq/clarification 0.1.1 npm Ambiguity resolution
@rtq/audit 0.1.1 npm Structured, redacted audit logging

📱 Mobile Package Enhancements (Rtq)

  • Renamed to Rtq (README header updated, APP_NAME = "Rtq").
  • Native OS screen‑lock:
    • Android: uses react-native-biometrics with BiometricPrompt and falls back to DEVICE_CREDENTIAL (PIN/pattern/password).
    • iOS: supports Face ID / Touch ID via the same library.
    • Added ensureBiometricAuth() helper (src/biometric.ts) and SimulatedDevice.approveWithBiometric() method that requires successful biometric verification before signing an approval.
  • Placeholder unsigned .ipa added to the package (included in files).

🚀 Quick Start

npm install @rtq/security   # core runtime
# or install the CLI globally
npm install -g @rtq/cli
import { createRTQ } from "@rtq/security";
const rtq = createRTQ({ signingKey: process.env.RTQ_SIGNING_KEY! });
// ...register capabilities, policies, authorize, execute

For mobile approval with biometric verification:

import { createMobileApprovalServer, SimulatedDevice } from "@rtq/mobile";
const server = await createMobileApprovalServer({ /* … */ });
const device = new SimulatedDevice({ name: "my‑device", keyPair: myKeyPair, pinnedHostPublicKey: hostPubKey });
await device.approveWithBiometric(challengePayload);

🔬 Verification

  • All 12 packages pass the CI suite (npm run ci).
  • New biometric flow is covered by unit tests (tests/mobile/biometric.test.ts).

💡 Why RTQ Was Created

While developing Aartiq, a disproportionate amount of engineering time was spent repeatedly implementing OS‑level sandboxing, capability scoping, fine‑grained permission gating, and challenge‑response authorization from scratch. RTQ was created to solve this problem for developers everywhere — packaging a security‑focused capability security runtime into a clean suite of reusable packages. Developed and validated through automated security testing, RTQ enables developers to integrate capability security, OS‑enforced sandboxing, Model Context Protocol (MCP) policy enforcement, and mobile QR challenge‑response approvals into their applications without having to build security infrastructure from scratch.