{"_id":"@acegalaxy/db-gateway","_rev":"3-41f0838e5097592e6339f05dbfca5681","name":"@acegalaxy/db-gateway","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@acegalaxy/db-gateway","version":"0.1.0","keywords":["database","gateway","postgres","sqlite","notion","authz","audit"],"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","_id":"@acegalaxy/db-gateway@0.1.0","maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"homepage":"https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs#readme","bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs/issues"},"dist":{"shasum":"f35dbe6c6a96abde522968c7d995475a0bca72bc","tarball":"https://registry.npmjs.org/@acegalaxy/db-gateway/-/db-gateway-0.1.0.tgz","fileCount":46,"integrity":"sha512-6W30Iigqb9BpK5KK9m7eanbcJG/pgxNW1nfgGoAZkRTs8ldxw7aqLg+zyums43LYROCEixtG0m6wnkgF6Pcldg==","signatures":[{"sig":"MEUCIQDkzyWC8DFgSGG+C7Wh3CJsikuRq2qzftZZ8Yp/a8rZ6wIgQrpuy877vNF332RD9DTgBRbwoVCAEIhovSnp+RnAB9Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33675},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./*":{"types":"./dist/*.d.ts","default":"./dist/*.js"}},"gitHead":"6678b4b3735ad2e18d96d1a50d6eca3500e7bb0f","private":false,"scripts":{"test":"node --test test/*.test.js","build":"tsc","clean":"rm -rf dist","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"kanelr","email":"lanhnk@acegalaxy.co"},"repository":{"url":"git+https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs.git","type":"git"},"_npmVersion":"11.12.1","description":"Multi-DB adapter (Postgres + SQLite + Notion) with a 5-layer default-deny security gateway: identity, policy authz (YAML), rate-limit, append-only audit log.","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@acegalaxy/security-utils":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/db-gateway_0.1.0_1778086026078_0.2176064259032251","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@acegalaxy/db-gateway","version":"0.1.1","keywords":["database","gateway","postgres","sqlite","notion","authz","audit"],"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","_id":"@acegalaxy/db-gateway@0.1.1","maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"homepage":"https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs#readme","bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs/issues"},"dist":{"shasum":"968974d47ca7195bc77f947c9409970643366f70","tarball":"https://registry.npmjs.org/@acegalaxy/db-gateway/-/db-gateway-0.1.1.tgz","fileCount":46,"integrity":"sha512-kvTtcjZxURM/pJQOh17aAb6QhocIe1gliQE5rTay39qOAtlFSle2Arl4tVZfTgl/d5g/rK7s+es7BgzCgMl2zg==","signatures":[{"sig":"MEUCIE1+/W/R+SHDrsElx2BhA+grIMVMfpkh5K5QTkPISpDRAiEAlTaeTNMpHE62A+ZSyleWqPKYXe8ZejGA1XQleNmlPVw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33628},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./*":{"types":"./dist/*.d.ts","default":"./dist/*.js"}},"gitHead":"7fd2da8e1531b28b6bd6d6f9797848add284241f","private":false,"scripts":{"test":"node --test test/*.test.js","build":"tsc","clean":"rm -rf dist","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"kanelr","email":"lanhnk@acegalaxy.co"},"repository":{"url":"git+https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs.git","type":"git"},"_npmVersion":"11.12.1","description":"Multi-DB adapter (Postgres + SQLite + Notion) with a 5-layer default-deny security gateway: identity, policy authz (YAML), rate-limit, append-only audit log.","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@acegalaxy/security-utils":"^0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/db-gateway_0.1.1_1778088196611_0.635514001357298","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@acegalaxy/db-gateway","version":"0.1.2","description":"Multi-DB adapter (Postgres + SQLite + Notion) with a 5-layer default-deny security gateway: identity, policy authz (YAML), rate-limit, append-only audit log.","main":"dist/index.js","scripts":{"test":"node --test test/*.test.js","build":"tsc","prepublishOnly":"npm run build","clean":"rm -rf dist","pretest":"npm run build"},"keywords":["database","gateway","postgres","sqlite","notion","authz","audit"],"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","private":false,"engines":{"node":">=20"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs.git"},"bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs/issues"},"homepage":"https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs#readme","dependencies":{"@acegalaxy/security-utils":"^0.1.2"},"types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./*":{"types":"./dist/*.d.ts","default":"./dist/*.js"},"./package.json":"./package.json"},"devDependencies":{"typescript":"^5.7.0","@types/node":"^20.0.0"},"gitHead":"7fd2da8e1531b28b6bd6d6f9797848add284241f","_id":"@acegalaxy/db-gateway@0.1.2","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-SL+EaSbsNNdgC3ToDXiMfPOvK1eB6u4ASlQBACrN3ilLw0AhCk6PGpc9T2aj5R/Nkg0/Ef8K0utHgm8HzK0ZqQ==","shasum":"451601b70f7f6cc37524543436f410c17161b824","tarball":"https://registry.npmjs.org/@acegalaxy/db-gateway/-/db-gateway-0.1.2.tgz","fileCount":46,"unpackedSize":33668,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDdtbjgoLdr2XiIc21NX83jUQWkFvsRn50waAuDCq4cZwIgIuLNaF9sOumHsM5T4gb1ikQsHuLIUcBjfXoqe+xSnXA="}]},"_npmUser":{"name":"kanelr","email":"lanhnk@acegalaxy.co"},"directories":{},"maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/db-gateway_0.1.2_1778088281655_0.0015972126857153324"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-06T16:47:05.990Z","modified":"2026-05-06T17:24:41.912Z","0.1.0":"2026-05-06T16:47:06.242Z","0.1.1":"2026-05-06T17:23:16.739Z","0.1.2":"2026-05-06T17:24:41.785Z"},"bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs/issues"},"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","homepage":"https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs#readme","keywords":["database","gateway","postgres","sqlite","notion","authz","audit"],"repository":{"type":"git","url":"git+https://github.com/acegalaxy-co/ace_commons-db-gateway-nodejs.git"},"description":"Multi-DB adapter (Postgres + SQLite + Notion) with a 5-layer default-deny security gateway: identity, policy authz (YAML), rate-limit, append-only audit log.","maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"readme":"# @acegalaxy/db-gateway\n\n[![npm version](https://img.shields.io/npm/v/@acegalaxy%2Fdb-gateway.svg)](https://www.npmjs.com/package/@acegalaxy/db-gateway)\n[![npm downloads](https://img.shields.io/npm/dm/@acegalaxy%2Fdb-gateway.svg)](https://www.npmjs.com/package/@acegalaxy/db-gateway)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![Node](https://img.shields.io/node/v/@acegalaxy%2Fdb-gateway.svg)](https://nodejs.org)\n\n\nMulti-database adapter with a 5-layer default-deny security gateway for\nPostgreSQL, SQLite, and Notion. Funnel every DB call through one entry point\nwith identity, policy authz, rate-limit, and append-only audit log.\n\n## Why\n\nAd-hoc DB calls scattered across a codebase are impossible to audit and easy to\nabuse. `db-gateway` centralizes access so every query passes the same checks:\n\n- **Who** is calling (identity resolution)\n- **What** they may touch (policy YAML, per-table/column)\n- **How fast** they may call (rate-limit / pool)\n- **What happened** (append-only audit log)\n\nThe gateway never throws; it returns `{ outcome, denyReason, rows?, latencyMs }`.\n\n## Install\n\n```bash\nnpm install @acegalaxy/db-gateway\n```\n\nRequires Node.js >= 20.\n\n## Quick start\n\n### PostgreSQL\n\n```js\nconst { Gateway } = require('@acegalaxy/db-gateway');\n\nconst gw = Gateway.create({\n  adapter: 'postgres',\n  connection: { host: 'localhost', database: 'app', user: 'app' },\n  policyPath: './policies/schema.yaml',\n  identity: (ctx) => ({ service: ctx.service, scope: ctx.scope }),\n  audit: (entry) => console.log(JSON.stringify(entry)),\n});\n\nconst res = await gw.query(\n  { op: 'select', table: 'users', where: { id: 42 } },\n  { service: 'web-api', scope: 'read' },\n);\n// { outcome: 'allow', rows: [...], latencyMs: 3 }\n```\n\n### Notion\n\n```js\nconst gw = Gateway.create({\n  adapter: 'notion',\n  connection: { token: process.env.NOTION_TOKEN },\n  policyPath: './policies/notion.yaml',\n  identity: (ctx) => ctx,\n  audit: writeAuditLog,\n});\n\nconst res = await gw.query(\n  { op: 'page.update', pageId: 'abc...', props: { Status: 'Done' } },\n  { service: 'sync-bot', scope: 'write' },\n);\n```\n\n## Adapters\n\n| Adapter    | Driver                | Status |\n| ---------- | --------------------- | ------ |\n| `postgres` | `pg`                  | beta   |\n| `sqlite`   | `better-sqlite3`      | beta   |\n| `notion`   | `@notionhq/client`    | beta   |\n\n## Security layers\n\n```\nCaller\n  │\n  ▼\n[L2] Identity resolver       ── who is this caller?\n  │\n  ▼\n[L3] Policy authz (YAML)     ── may they touch this table/column?\n  │\n  ▼\n[L4] Rate-limit + pool       ── too many calls? back off.\n  │\n  ▼\n[L5] Audit log (append-only) ── record outcome + latency\n  │\n  ▼\n[L1] Adapter (driver call)   ── only place that imports pg / sqlite / notion\n```\n\nDefault-deny: missing policy entry = `deny`. Hard `DELETE` is blocked on tables\nwith `soft_delete` policy. `notion.pages.delete()` is never called — archive only.\n\n## License\n\n[MIT](./LICENSE) © 2026 ACE Galaxy\n\n## Contributing\n\nSee [CONTRIBUTING.md](./CONTRIBUTING.md) and [CODE_OF_CONDUCT.md](./CODE_OF_CONDUCT.md).\nSecurity issues: see [SECURITY.md](./SECURITY.md).\n","readmeFilename":"README.md"}