New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

@codragraph/org

Package Overview
Dependencies
Maintainers
1
Versions
11
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@codragraph/org

Multi-tenant orgs, SSO, RBAC, and tamper-evident audit logging for the CodraGraph platform.

latest
Source
npmnpm
Version
2.2.0
Version published
Weekly downloads
1
-80%
Maintainers
1
Weekly downloads
 
Created
Source

@codragraph/org

Multi-tenant orgs, SSO, RBAC, and tamper-evident audit logging for the CodraGraph platform.

This is Phase 5 of the CodraGraph roadmap: the org-features layer that turns the local-first OSS into something that can be operated for multiple teams or customers under one server.

Use this package when you are wrapping the local-first @codragraph/cli indexing workers, FeatureCluster context packs, and graphstore snapshots in tenant, RBAC, and audit boundaries for a hosted or enterprise deployment.

What's in here

ModuleWhat it does
tenancywithTenant / requireTenant AsyncLocalStorage scoping. Path helpers that refuse to escape the org root.
rbacviewer < member < admin < owner. Default policy covers repos, FeatureCluster context packs/impact, graphstore, recipes, audit, and org administration; integrators extend by composing additional entries.
auditAppend-only, tamper-evident log. Each event is a content-addressed object (sha256 of canonical JSON = the id). Re-hashing verifies. Re-uses @codragraph/graphstore's CAS for storage.
authProvider-agnostic SsoProvider interface. Includes InMemorySsoProvider for tests. OIDC and SAML reference impls land in follow-ups.

Install

npm install @codragraph/org

Quick start

import {
  CasAuditLogger,
  DEFAULT_POLICY,
  checkPermission,
  makeOrgId,
  makeUserId,
  withTenant,
} from "@codragraph/org";
import { FsCAS } from "@codragraph/graphstore/dist/cas/fs-cas.js";

const cas = new FsCAS({ root: "/var/codragraph/cas" });
const audit = new CasAuditLogger(cas, "/var/codragraph/audit");

await withTenant({ orgId: makeOrgId("org_acme") }, async () => {
  if (!checkPermission(DEFAULT_POLICY, "member", "repo.analyze")) return;
  // ... do work ...
  await audit.record({
    ts: new Date().toISOString(),
    orgId: makeOrgId("org_acme"),
    actor: { kind: "user", userId: makeUserId("user_alice") },
    action: "repo.analyze",
    resource: { type: "repo", id: "demo" },
    result: "success",
  });
});

License

Apache-2.0. You can use, modify, redistribute, bundle, and host this package commercially, subject to the Apache-2.0 notice and attribution requirements.

Keywords

codragraph

FAQs

Package last updated on 14 Jun 2026

Related posts