TypeScript First Admission and Historical Trust
TypeScript First Admission and Historical Trust
Section titled “TypeScript First Admission and Historical Trust”The TypeScript AdmissionService layers First Admission and Historical Trust
above the six-stage Signed Document verifier
(MWP-ADM-005).
The language-independent flow is the local
First Admission and Historical Trust runtime page,
and the exact requirements are the local
First-Admission and Historical-Trust clauses.
Public adapters and results
Section titled “Public adapters and results”| Public API | Responsibility |
|---|---|
AdmissionCurrentKeyResolver.resolveCurrent |
Synchronously return complete Organization-wide Registry evidence that the deployment asserts is current for this decision. |
TrustedAdmissionContext.issue |
Synchronously or asynchronously issue the trusted record ID, acceptance instant, and accepting service only after authoritative absence. |
AdmissionLog.lookup |
Asynchronously return { status: "found", record } or { status: "authoritative-absence" }. Cache miss, timeout, unauthenticated absence, and indeterminate state fail closed under MWP-ADM-003. |
AdmissionLog.appendOrReturnExisting |
Atomically append candidate bytes or return the concurrent authoritative winner through an authenticated service identity. |
AuthenticatedAdmissionRecord |
Bind recordBytes to the service authenticated by the adapter so MWP-ADM-009 can validate the returned record. |
AdmissionService.prepareFirstAdmission |
Create and validate candidate evidence from an SDK-produced VerifiedSignedDocument. It does not append or imply admission. |
AdmissionService.admitFirst |
Perform current verification, authoritative lookup, candidate creation, atomic append-or-return-existing, and returned-record validation under MWP-ADM-006. |
AdmissionService.verifyHistoricalAdmission |
Rerun six-stage verification with historical Registry evidence and require an existing record without issuing context or appending, as required by MWP-ADM-008. |
AdmittedSignedDocument |
Return immutable verified and record evidence plus a defensive recordBytes copy. |
The exact authoritative absence value is { status: "authoritative-absence" }.
A caller-provided trust boolean is not an Admission lookup outcome and must
never select the success path.
First-admission call order
Section titled “First-admission call order”admitFirst completes all six signed-document stages before consulting the log.
A found record is validated and returned without issuing trusted context or
appending. After authoritative absence, the service issues trusted context,
prepares canonical candidate bytes, calls appendOrReturnExisting, and
validates the record actually returned. A concurrent winner is acceptable only
when its Schema, authenticated service, document binding, and trusted time pass
MWP-ADM-009
and
MWP-ADM-010.
Historical replay
Section titled “Historical replay”Historical replay reruns verification with retained Registry history, requires
status: "found", and never calls TrustedAdmissionContext.issue or
AdmissionLog.appendOrReturnExisting. Matching record IDs demonstrate recovery
of the same authoritative record; they do not prove Command freshness, signer
authorization, state-machine acceptance, or portable log-proof verification.
Those remain separate under
MWP-ADM-013
and
MWP-ADM-014.
Error surface
Section titled “Error surface”AdmissionError exposes wireCode: "AUTH_INVALID_SIGNATURE" and protected
auditDetail.stage: "admission". Stable protected reasons distinguish missing,
conflicting, malformed, unauthenticated, unavailable, indeterminate, and
self-anchoring evidence while preserving the non-oracular wire result required
by
MWP-ADM-012.
Adapters may throw AdmissionLogError with a supported Admission reason. Other
adapter exceptions are not automatically recategorized. Deployments must map
their failures deliberately and must not treat generic success, availability, or
cache state as authenticated evidence.