Skip to content

TypeScript First Admission and Historical Trust

TypeScript First Admission and Historical Trust

Section titled “TypeScript First Admission and Historical Trust”

The TypeScript AdmissionService layers First Admission and Historical Trust above the six-stage Signed Document verifier (MWP-ADM-005). The language-independent flow is the local First Admission and Historical Trust runtime page, and the exact requirements are the local First-Admission and Historical-Trust clauses.

Public API Responsibility
AdmissionCurrentKeyResolver.resolveCurrent Synchronously return complete Organization-wide Registry evidence that the deployment asserts is current for this decision.
TrustedAdmissionContext.issue Synchronously or asynchronously issue the trusted record ID, acceptance instant, and accepting service only after authoritative absence.
AdmissionLog.lookup Asynchronously return { status: "found", record } or { status: "authoritative-absence" }. Cache miss, timeout, unauthenticated absence, and indeterminate state fail closed under MWP-ADM-003.
AdmissionLog.appendOrReturnExisting Atomically append candidate bytes or return the concurrent authoritative winner through an authenticated service identity.
AuthenticatedAdmissionRecord Bind recordBytes to the service authenticated by the adapter so MWP-ADM-009 can validate the returned record.
AdmissionService.prepareFirstAdmission Create and validate candidate evidence from an SDK-produced VerifiedSignedDocument. It does not append or imply admission.
AdmissionService.admitFirst Perform current verification, authoritative lookup, candidate creation, atomic append-or-return-existing, and returned-record validation under MWP-ADM-006.
AdmissionService.verifyHistoricalAdmission Rerun six-stage verification with historical Registry evidence and require an existing record without issuing context or appending, as required by MWP-ADM-008.
AdmittedSignedDocument Return immutable verified and record evidence plus a defensive recordBytes copy.

The exact authoritative absence value is { status: "authoritative-absence" }. A caller-provided trust boolean is not an Admission lookup outcome and must never select the success path.

admitFirst completes all six signed-document stages before consulting the log. A found record is validated and returned without issuing trusted context or appending. After authoritative absence, the service issues trusted context, prepares canonical candidate bytes, calls appendOrReturnExisting, and validates the record actually returned. A concurrent winner is acceptable only when its Schema, authenticated service, document binding, and trusted time pass MWP-ADM-009 and MWP-ADM-010.

Historical replay reruns verification with retained Registry history, requires status: "found", and never calls TrustedAdmissionContext.issue or AdmissionLog.appendOrReturnExisting. Matching record IDs demonstrate recovery of the same authoritative record; they do not prove Command freshness, signer authorization, state-machine acceptance, or portable log-proof verification. Those remain separate under MWP-ADM-013 and MWP-ADM-014.

AdmissionError exposes wireCode: "AUTH_INVALID_SIGNATURE" and protected auditDetail.stage: "admission". Stable protected reasons distinguish missing, conflicting, malformed, unauthenticated, unavailable, indeterminate, and self-anchoring evidence while preserving the non-oracular wire result required by MWP-ADM-012.

Adapters may throw AdmissionLogError with a supported Admission reason. Other adapter exceptions are not automatically recategorized. Deployments must map their failures deliberately and must not treat generic success, availability, or cache state as authenticated evidence.