AbsoluteJS

@absolutejs/secure-messaging-federation-https

@absolutejs/secure-messaging-federation-httpsv0.0.3betaMessaging

Hardened HTTPS and mutual-TLS transport adapter for AbsoluteJS secure messaging federation.

#Installation

BASH
bun add @absolutejs/secure-messaging-federation-https

#Capabilities

Overview

Hardened HTTPS transport for @absolutejs/secure-messaging-federation.

Provider discovery is fixed at

/.well-known/absolutejs-secure-messaging-federation.

Show 8 more

Delivery is fixed at the advertised protocol path and never follows redirects.

The Node/Bun client presents its certificate and key, validates the server CA

and DNS identity, pins the resolved addresses for the request, and then enforces advertised SHA-256 certificate rotation pins. Up to 16 addresses are attempted with bounded 250 ms staggering; the first authenticated HTTPS response wins and every remaining attempt is aborted.

Private, loopback, link-local, metadata-service, and special-use addresses are

rejected by default. allow-private is an explicit development/private-mesh mode and must never be enabled for public tenant-controlled domains.

Strict bounded batches carry only already-signed federation envelopes.

The package does not terminate inbound TLS itself. A server or PaaS gateway must require and validate client certificates, derive authenticatedPeerDomain from the verified certificate, and pass that identity to acceptFederationHttpsRequest. The function checks it against both the request origin header and every envelope origin before enqueueing.

This is the stable AbsoluteJS ABS-FED-HTTPS-1 transport, not a claim of MIMI wire interoperability. MIMI tracking remains in the revision-pinned adapter. Address ordering and staggered connection attempts follow the operational model in RFC 8305 without performing a second DNS lookup or weakening certificate identity checks.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/secure-messaging-federation-https through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/secure-messaging-federation-https version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/secure-messaging-federation-https example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#Public entry points

Supported entry points declared by this package manifest.

Package entry point declared in package.json.

@absolutejs/secure-messaging-federation-https@absolutejs/secure-messaging-federation-https/manifest@absolutejs/secure-messaging-federation-https/manifest.json

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --root src --sourcemap --target=node --external @absolutejs/secure-messaging-federation --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

23 symbols
isPublicFederationAddressvaluePermalinkSource
TS
const isPublicFederationAddress: (address: string) => boolean;
Exported from @absolutejs/secure-messaging-federation-https