feat(routes)!: createMailboxRoutes(deps) replaces mountMailbox - #37
Merged
TheGreatAxios merged 1 commit intoSep 27, 2026
Conversation
This was referenced Sep 25, 2026
TheGreatAxios
commented
Sep 25, 2026
TheGreatAxios
left a comment
Contributor
Author
There was a problem hiding this comment.
Self-review: the branch went through two independent review passes, and every finding is fixed. Two findings were waived after a senior ruling: the README stays stale on #37 until #38 lands, and the default resolver has no null guard because TenantEnv guarantees tenant and principal. Build, typecheck and 171 tests pass against real Postgres.
TheGreatAxios
force-pushed
the
cl-9067-mailbox-replace-mountmailbox-with-createmailboxroutesdeps
branch
from
September 25, 2026 17:52
abb20e4 to
826be3d
Compare
TheGreatAxios
force-pushed
the
cl-9067-mailbox-replace-mountmailbox-with-createmailboxroutesdeps
branch
from
September 26, 2026 01:28
826be3d to
111e81b
Compare
TheGreatAxios
added this pull request to stack #47
September 26, 2026 01:58
The routes are now a Hono<TenantEnv> sub-app the host mounts with app.route, the shape Interchange's own route factories use. Every route is gated through deps.requireGrant on mailbox:* (read, create for send, manage for flag and move). The principal comes only from the tenant and principal the host's tenant middleware set, the same one requireGrant authorizes; every route returns 403 when the context carries none. Closes CL-9067, CL-9070.
TheGreatAxios
force-pushed
the
cl-9067-mailbox-replace-mountmailbox-with-createmailboxroutesdeps
branch
from
September 26, 2026 02:40
111e81b to
eafd2ea
Compare
TheGreatAxios
removed this pull request from stack #47
September 26, 2026 02:40
TheGreatAxios
added this pull request to stack #50
September 26, 2026 02:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
createMailboxRoutes(deps): Hono<TenantEnv>returns a sub-app the host mounts withapp.route;mountMailboxis deleted with no alias.MountMailboxOptsis nowCreateMailboxRoutesDeps.deps.requireGrant: readsmailbox:* read, sendcreate, flag and movemanage.requireGrantauthorizes; theresolvePrincipaloption is removed. Every route returns 403 when the context carries no principal.@intx/hub-api^0.4.0is a new peer (types only).Verification
New tests cover the grant resource and action per route and principal resolution behind a TenantEnv middleware. CI is green on this branch: install
--frozen-lockfile, build, typecheck, tests against Postgres, and the Node consumer smoke test.Closes CL-9067
Closes CL-9070