Documentation
    Preparing search index...

    Interface ResourceServiceOptions

    Options for createResourceService (options-as-bridge per v1.6 Decision 18).

    fetch is the only required field. Kehto does not select a runtime's scheme or origin policy. The optional origin-policy fields form one adapter and must therefore be supplied together when a runtime chooses to use it.

    interface ResourceServiceOptions {
        resourceInfo?: ResourceInfoProvider;
        fetch(url: string, init: ResourceFetchInit): Promise<Response>;
        getConnectGrants?(dTag: string, aggregateHash: string): readonly string[];
        isOriginGranted?(origin: string, grants: readonly string[]): boolean;
        resolveIdentity?(
            windowId: string,
        ): { aggregateHash: string; dTag: string } | null;
    }
    Index

    Properties

    resourceInfo?: ResourceInfoProvider

    Advisory NAP-RESOURCE introspection exposed through resource.info.

    Provide a static snapshot or a resolver when the shell wants to disclose configured schemes and coarse limits. Scheme disclosure is advisory and is never used as fetch authorization. Omit to disclose no schemes or limits.

    Methods

    • Runtime-supplied resource resolver. Receives the requested URL and returns a byte-classified Response.

      The runtime owns scheme dispatch and every NAP-RESOURCE policy decision. The returned content-type must describe the runtime-classified bytes, not an untrusted upstream header. Throw ResourceServiceError to preserve a canonical protocol error classification.

      Parameters

      • url: string

        The URL from the resource.bytes request

      • init: ResourceFetchInit

        Read-only method, request-scoped AbortSignal, and optional advisory Blossom servers

      Returns Promise<Response>

    • Returns the list of allowed fetch origins for the given napplet identity. Called on every resource.bytes request — must be synchronous and fast. Optional and paired with isOriginGranted plus resolveIdentity.

      Host-supplied grant source (e.g. a static per-dTag allowlist map, or any other host-controlled policy). Returns an empty array to deny all origins.

      Parameters

      • dTag: string

        The napplet's d-tag (from session registry)

      • aggregateHash: string

        The napplet's aggregate hash (from session registry)

      Returns readonly string[]

    • Returns true if origin is present in grants (the list returned by getConnectGrants for the napplet's dTag + aggregateHash). Optional: when omitted with getConnectGrants, Kehto delegates directly to the runtime resolver without an origin-grant decision.

      The reference implementation is simply grants.includes(origin). Host apps may provide normalized-origin comparison if needed.

      Parameters

      • origin: string

        Parsed origin of the requested URL (scheme + host + port)

      • grants: readonly string[]

        Readonly list from getConnectGrants for this napplet identity

      Returns boolean

    • Resolve a windowId to the napplet's identity (dTag + aggregateHash). Returns null if the window is not in the session registry.

      Typically wraps sessionRegistry.getEntryByWindowId(windowId).

      Parameters

      • windowId: string

        The iframe window identifier

      Returns { aggregateHash: string; dTag: string } | null