Skip to content

Run host code inside an Arc service scope - #94

Merged
woksin merged 11 commits into
mainfrom
feature/run-in-scope
Sep 26, 2026
Merged

woksin merged 11 commits into
mainfrom
feature/run-in-scope

Conversation

@woksin

@woksin woksin commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Arc for TypeScript 0.40.0 adds a supported way for host integrations to run code inside an existing Arc service scope, the first step toward constructing Chronicle reactors and reducers through Arc's dependency injection. npm publication remains disabled.

Added

  • ArcServer.runInScope(scope, callback, options?) runs a callback inside an existing service scope, with currentServices() and currentContext() set as they are for a request. Only the correlation ID and an extra abort signal can be supplied (RunInScopeOptions); tenant, principal, transport and severity come from the scope. Only scopes created with server.services.createScope(context) can be borrowed; Arc's own request, query and observable-query scopes cannot. It rejects scopes from another server, singleton, closed or fabricated scopes, and scopes whose principal is not plain data. It is a trusted host API, not an authorization mechanism: commands still go through the normal pipeline.

Changed

  • A service scope captures an immutable snapshot of its execution context when it is created. ServiceScope.identity returns that snapshot, and the Chronicle, MongoDB and Drizzle integrations use it, so changing the original context object after a scope was created no longer changes the tenant those services use. Principals whose claims can't be cloned keep working for ordinary requests.

Refs #93

Capture scope authority at admission so host integrations can vary correlation and link cancellation without substituting a mutable principal or tenant. Share the ambient boundary with owned operations while retaining their cleanup behavior and singleton failure handling.
@woksin woksin added the minor New backward-compatible capabilities label Sep 26, 2026
@woksin woksin self-assigned this Sep 26, 2026
Structured cloning silently strips prototype-backed identity fields, leaving borrowed scopes with incomplete authority. Preserve original principals for ordinary requests while detaching and validating plain-principal snapshots. Document the creation-time factory context and borrowed-scope boundary.
Capture declared execution fields through getters while keeping the original principal for ordinary scopes. Borrow only deeply frozen plain-data principals, rejecting lossy shapes before running callbacks.
Factory contexts must not capture an invocation's correlation or linked cancellation signal, because scoped services persist across invocations. Keep per-invocation overrides only in the ambient request context and document the two lifetimes.
Construct scoped and transient services under their owning scope snapshot so invocation-only cancellation, correlation and principal copies cannot leak into cached services.
runInScope reported an unsnapshotable principal for every non-borrowable
scope, including Arc-owned request scopes whose principal was never
inspected.
@woksin
woksin merged commit 08ff532 into main Sep 26, 2026
3 checks passed
@cratis-direct
cratis-direct Bot deleted the feature/run-in-scope branch September 26, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

minor New backward-compatible capabilities

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant