AbsoluteJS

@absolutejs/secure-messaging-postgres

@absolutejs/secure-messaging-postgresv0.2.1betaMessaging

Tenant-scoped atomic PostgreSQL SecureMessagingStore for AbsoluteJS.

#Installation

BASH
bun add @absolutejs/secure-messaging-postgres

#Capabilities

Overview

The recommended production SecureMessagingStore for AbsoluteJS. One database transaction atomically commits sealed MLS state, an inbound replay receipt, and encrypted outbox entries. Conversation updates use revision compare-and-swap.

createNodePostgresSecureMessagingClient(pool) supports pg pools without making either driver a runtime dependency.

durability is mandatory. local-wal forces synchronous_commit=on for every adapter transaction, regardless of a weaker session or database default. synchronous-replica forces synchronous_commit=remote_apply and must only be used with an intentionally configured synchronous standby. It can block when that standby is unavailable, so rehearse failover and define an operator-owned availability policy instead of weakening durability silently. Both modes fail closed when PostgreSQL reports fsync=off; the replica mode also rejects an empty synchronous_standby_names setting.

Show 5 more

Apply the exported SECURE_MESSAGING_POSTGRES_MIGRATION or the packaged ./migrations/postgres.sql through your migration system. The migration is idempotent. Call deleteExpiredInbound() repeatedly from a maintenance job until it returns zero.

Tenant/device scope, conversation, message, and queue identifiers are SHA-256 digested before use as keys. Device scope is mandatory because two devices hold different MLS state for the same conversation. Delivery routing metadata and encrypted frames remain visible to the database; message plaintext and unsealed MLS state do not.

Run @absolutejs/secure-messaging-store-conformance against an isolated tenant after database upgrades and restore drills.

This release accepts the @absolutejs/secure-messaging@0.6 store contract and classifies mutation response loss as SecureMessagingDurabilityUncertainError. Reconnect to the authoritative database and call resolveSecureMessagingStoreCommit() before retrying a conversation commit.

Licensed under Apache-2.0.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/secure-messaging-postgres through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/secure-messaging-postgres version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/secure-messaging-postgres example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#@absolutejs/secure-messaging-postgres quick start

Partial snippet

# @absolutejs/secure-messaging-postgres

TS
import postgres from "postgres";
import {
  createPostgresJsSecureMessagingClient,
  createPostgresSecureMessagingStore,
} from "@absolutejs/secure-messaging-postgres";

const sql = postgres(process.env.DATABASE_URL!);
const store = createPostgresSecureMessagingStore({
  client: createPostgresJsSecureMessagingClient(sql),
  deviceId: authenticatedDevice.id,
  durability: "local-wal",
  tenantId: authenticatedTenant.id,
});

#Public entry points

Supported entry points declared by this package manifest.

Package entry point declared in package.json.

@absolutejs/secure-messaging-postgres@absolutejs/secure-messaging-postgres/migrations/postgres.sql

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/secure-messaging && tsc --project tsconfig.build.json
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run test:integrationbun test tests/postgres.test.ts
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

13 symbols
SecureMessagingPostgresQueryResulttypePermalinkSource
TS
type SecureMessagingPostgresQueryResult<Row> = {
    readonly rowCount: number;
    readonly rows: readonly Row[];
};
Exported from @absolutejs/secure-messaging-postgres