Skip to content

Drop the server tier: scope primitives-ts to the browser and Node scripts - #71

Merged
verygoodsoftwarenotvirus merged 2 commits into
mainfrom
chore/drop-server-tier-packages
Sep 20, 2026
Merged

verygoodsoftwarenotvirus merged 2 commits into
mainfrom
chore/drop-server-tier-packages

Conversation

@verygoodsoftwarenotvirus

Copy link
Copy Markdown
Contributor

Why

No service is written in TypeScript — platform-go is the only server tier there is. Packages whose reason to exist was sitting beside a database, a broker, an object store or a secret manager have no consumer in this module and never will. Anything that needs to talk to a service built on platform-go belongs in platform-client-ts, not here.

This is scope correction, not catch-up. The module was authored before the primitives/platform split had a name, back when "port platform" meant "port all of it".

What goes

Package Why
authentication Argon2 hashing, token issuing, TOTP provisioning — a client issues nothing
authorization Policy evaluation is authoritative on the server; clients read permissions off the API
database SQL abstraction + migrations
distributedlock Nothing on a page takes a distributed lock
email Sending
healthcheck Readiness probes over DB/cache/queue
idempotency Server-side at-most-once execution
llm Provider keys don't belong on a client
messagequeue Publisher/consumer
notifications Providers are apns.node, fcm.node, ably.node, pusher.node — all server-side sending
search Index/search backends
secrets Secret manager access
uploads filesystem/s3/gcp sinks; the client-side presign → PUT → confirm flow is platform-client-ts's job

What stays, reclassified

featureflags and qrcodes were filed under Server-only but are kept — they move to isomorphic and universal respectively. With nothing left in it, the server-only modality is removed from README.md and CLAUDE.md, leaving universal and isomorphic.

Notes for review

  • No kept package imported a dropped one — the cut is clean at the dependency level, verified by grep over both package.json deps and .ts source.
  • README now states that parity with primitives-go is deliberately partial — absent packages are out of scope, not pending.
  • Follow-up, deliberately not in this PR: some kept packages still carry server-shaped providers — cache/providers/redis.node.ts, ratelimiting/providers/redis.node.ts (both pulling ioredis), and featureflags' @launchdarkly/node-server-sdk / @openfeature/server-sdk. Trimming those changes public provider registries, so it wants its own PR and its own look.

Verification

Uncached (turbo cache cleared, --force): build 24/24 · typecheck 28/28 · test 28/28 · lint 28/28.

🤖 Generated with Claude Code

…ode scripts

No service is written in TypeScript — platform-go is the only server tier there is —
so the packages whose reason to exist was sitting beside a database, a broker, an
object store or a secret manager have no consumer here and never will. Code that needs
to talk to a service built on platform-go belongs in platform-client-ts.

Removes 13 packages: authentication (Argon2/token issuing), authorization, database,
distributedlock, email, healthcheck (readiness probes over DB/cache/queue), idempotency,
llm, messagequeue, notifications (apns/fcm/ably/pusher — all server-side *sending*),
search, secrets, uploads (filesystem/s3/gcp sinks).

No kept package imported a dropped one, so the cut is clean at the dependency level.
featureflags and qrcodes were filed under "Server-only" but are kept and reclassified
isomorphic and universal respectively; the server-only modality is gone from both
README.md and CLAUDE.md, leaving universal and isomorphic.

Verified uncached: build 24/24, typecheck 28/28, test 28/28, lint 28/28.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- Remove the pending changesets for authorization, database and idempotency — their
  packages left in the previous commit, so `changeset version` would have failed on
  releases that can no longer exist.
- Add a release-neutral changeset for the removal itself. No kept package imported a
  dropped one, so no surviving package's code or public surface changed.
- Rename the private workspace root to @primandproper/primitives-ts.
- Reformat README.md (prettier).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This was referenced Sep 20, 2026
@verygoodsoftwarenotvirus
verygoodsoftwarenotvirus merged commit f63f030 into main Sep 20, 2026
6 checks passed
@verygoodsoftwarenotvirus
verygoodsoftwarenotvirus deleted the chore/drop-server-tier-packages branch September 20, 2026 17:38
verygoodsoftwarenotvirus added a commit that referenced this pull request Sep 20, 2026
* chore: remove identifiers — a client does not issue the server's IDs

primitives-conformance turned up that the four ports disagree on what
`identifiers` means: Go uses xid (rs/xid, 20 chars), Swift matches it, Kotlin
generates 26-char ULIDs and this package generated 21-char nanoids. Go's
Validate rejects the last two, so a TypeScript client generating an ID and
sending it to a platform-go service is rejected at the door.

The fix is not to reimplement xid in TypeScript. A client has no business
generating a server's identifiers: the server issues them, the client receives
opaque strings, and validating an ID the server just sent proves nothing. This
is a server-tier package that survived #71 only because its name does not sound
like infrastructure.

Nothing imported it — its only consumer was idempotency, removed in #71 — so
deleting the directory is the whole change. nanoid and ulid leave the
dependency tree with it.

Verified uncached: build 23/23, typecheck/test/lint 27/27, format clean.

Closes #75

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore: declare the removal as a changeset

The changeset gate still guards main until the tag-driven release change lands,
and a package leaving the workspace is worth a release note either way.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant