{"_id":"@artifactshare/qm-bridge","name":"@artifactshare/qm-bridge","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@artifactshare/qm-bridge","version":"0.1.0","description":"Host-side trust-boundary library for sharing qm output through Artifact Share.","keywords":["ai-agents","artifact-share","bridge","cloudflare-workers","qm"],"homepage":"https://artifactshare.com/connect","license":"SEE LICENSE IN LICENSE","repository":{"type":"git","url":"git+https://github.com/artifactshare/artifactshare.git","directory":"packages/qm-bridge"},"bin":{"artifactshare-qm-bridge":"dist/cli.js"},"type":"module","sideEffects":false,"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./client":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./qm":{"types":"./dist/qm.d.ts","import":"./dist/qm.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.js"}},"publishConfig":{"access":"public"},"devDependencies":{"@types/node":"22.20.1","tsdown":"0.22.14","typescript":"7.0.2","vitest":"4.1.10"},"engines":{"node":">=22.19.0"},"scripts":{"build":"tsdown","test":"pnpm run build && vitest run","typecheck":"tsc --noEmit"},"_id":"@artifactshare/qm-bridge@0.1.0","bugs":{"url":"https://github.com/artifactshare/artifactshare/issues"},"_integrity":"sha512-MwIbv8yxoYxH/Uqsub2PqoWMSCm++RZOSzQ9UkqkbnLR4lgjrH9GMinbHBa0K7xHx5krPBAXcDixWcdh0prrBQ==","_resolved":"/home/runner/work/_temp/release/artifactshare-qm-bridge-0.1.0.tgz","_from":"file:artifactshare-qm-bridge-0.1.0.tgz","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-MwIbv8yxoYxH/Uqsub2PqoWMSCm++RZOSzQ9UkqkbnLR4lgjrH9GMinbHBa0K7xHx5krPBAXcDixWcdh0prrBQ==","shasum":"4a70c04c13024b598969e385b16d7e06c97c5751","tarball":"https://registry.npmjs.org/@artifactshare/qm-bridge/-/qm-bridge-0.1.0.tgz","fileCount":15,"unpackedSize":109939,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@artifactshare%2fqm-bridge@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCxC8W6N109fS42F07Tyqgzy7dZdbxS77UKQuGHWuYJ2AIhAOkuuHg9/OAYYSYlUZr3ONgJ7Wahwj2PBllpQzcie6d3"}]},"_npmUser":{"name":"coji","email":"coji@techtalk.jp"},"directories":{},"maintainers":[{"name":"coji","email":"coji@techtalk.jp"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/qm-bridge_0.1.0_1787728174794_0.08934216387080984"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-26T07:09:34.610Z","0.1.0":"2026-08-26T07:09:34.946Z","modified":"2026-08-26T07:09:35.368Z"},"maintainers":[{"name":"coji","email":"coji@techtalk.jp"}],"description":"Host-side trust-boundary library for sharing qm output through Artifact Share.","homepage":"https://artifactshare.com/connect","keywords":["ai-agents","artifact-share","bridge","cloudflare-workers","qm"],"repository":{"type":"git","url":"git+https://github.com/artifactshare/artifactshare.git","directory":"packages/qm-bridge"},"bugs":{"url":"https://github.com/artifactshare/artifactshare/issues"},"license":"SEE LICENSE IN LICENSE","readme":"# @artifactshare/qm-bridge\n\nThis is a host-side service library, not a sharing CLI for a model shell. Do not expose its credential provider or trusted context to a model sandbox.\n\nThe package separates untrusted share intent, host-authenticated context, and the Artifact Share bridge credential. The server remains authoritative for conversation mapping, destination, grants, and the final audience ceiling.\n\n## Install\n\n```sh\nnpm install @artifactshare/qm-bridge\n```\n\nThe root export provides `validateBridgeConfig`, `createBridgePolicy`, and `publishTrusted`. `@artifactshare/qm-bridge/client` provides the fetch-based Artifact Share client. Root, client, and testing exports contain no Node-only imports and can be bundled for Cloudflare Workers. The `qm` subpath only normalizes fields that a protected qm host has already authenticated; it does not read environment variables or infer trust.\n\n## Minimal host integration\n\n```ts\nimport {\n  createBridgePolicy,\n  publishTrusted,\n  validateBridgeConfig,\n} from '@artifactshare/qm-bridge'\nimport { createArtifactShareBridgeClient } from '@artifactshare/qm-bridge/client'\n\nconst config = validateBridgeConfig(parsedConfig)\nconst result = await publishTrusted({\n  intent: untrustedModelIntent,\n  context: authenticatedHostContext,\n  policy: createBridgePolicy(config),\n  client: createArtifactShareBridgeClient({\n    baseUrl: config.base_url,\n    timeoutMs: config.request_timeout_ms,\n  }),\n  credentialProvider: async () => ({\n    bearer_token: await hostSecretStore.read(),\n  }),\n})\n```\n\nThe host must reuse the same host-generated request ID when retrying. The library performs one request and no hidden retry. A requested workspace audience is only intent: private or stale host context and server policy can narrow it. A successful workspace `set_visibility` request may therefore return current `private` visibility without being treated as an error.\n\nEvery `BridgeClient` declares the exact `credentialOrigin` that receives the bridge credential. `publishTrusted` rejects a client whose origin differs from the policy before reading the credential.\n\n## Configuration\n\nThe JSON configuration contains `base_url`, a bound `source`, optional `request_timeout_ms` and `max_payload_bytes`, and a nonempty `allowed_conversations` array. The allowlist compares the current authenticated conversation ID; former IDs support server-side mapping continuity but never authorize a request.\n\nThe Node operator executable reads only `ARTIFACTSHARE_BRIDGE_TOKEN`, and only `health` uses its value:\n\n```sh\nartifactshare-qm-bridge check --config bridge.json --json\nartifactshare-qm-bridge health --config bridge.json --json\nartifactshare-qm-bridge dry-run --config bridge.json --intent intent.json --context context.json --json\n```\n\nAll commands require `--json`. Invalid command syntax returns exit 2 with `error.code: \"invalid_cli_usage\"`; scripts should parse that code to distinguish usage errors from a reachable bridge rejection. `dry-run` is offline and anchors public freshness to the fixture timestamp, so `fixture_anchor_valid` checks syntax and the freshness code path, not wall-clock freshness. Exit 0 is success, 2 is invalid input or application rejection, 3 is unavailable credential/network/timeout, and 1 is an invalid server response or unexpected failure.\n\n## Lifecycle\n\nThe package has no install or postinstall script. Initial npm publication is a separate owner-approved production operation through the protected release workflow; merging this package does not publish it. For the first publication only, configure the production environment secret `NPM_QM_BRIDGE_BOOTSTRAP_TOKEN`. After the package exists, configure npm trusted publishing for `release-qm-bridge.yml` and the `production` environment, then delete the bootstrap secret. Later releases use OIDC with no npm write token. A future Cloudflare OS Gatekeeper can use the host-neutral root and client exports without importing the qm subpath.\n","readmeFilename":"README.md","_rev":"1-e3ec720ddfdbdbcacbab03634219eed3"}