Skip to content

Instantly share code, notes, and snippets.

View Walid-Azur's full-sized avatar

Walid Boudabbous Walid-Azur

  • Dudoxx/Acceleate
  • Hamburg
View GitHub Profile
@Walid-Azur
Walid-Azur / permission.guard.ts
Created September 8, 2026 10:13
Fail-closed RBAC in NestJS: the guard-vs-interceptor ordering trap that becomes an auth bypass
// =============================================================================
// api-service — PermissionGuard (fail-closed RBAC — Invariant #2, THE headline fix)
// =============================================================================
// Acceleate Consulting - Walid Boudabbous <walid@acceleate.com>
//
// Guard chain position 5 (last): Throttler → GatewayAuth → ApiKey →
// [PrincipalContextInterceptor] → PermissionGuard. Registered AFTER the auth
// guards so `request.principal` is set... EXCEPT: NestJS runs ALL guards before
// ANY interceptor, so PrincipalContextInterceptor has NOT run when this guard
// executes. This guard therefore re-derives the acting principal from whichever
@Walid-Azur
Walid-Azur / rag-chunking-provenance.ts
Created September 8, 2026 10:13
RAG chunking that can cite itself: deterministic ids + char-offset provenance
/**
* Chunking + provenance (W1).
*
* Two things the earlier PoC got wrong and this fixes:
*
* 1. THE BENCHMARK DID NOT CHUNK. `run-bench.ts` inlined its own ingest and stored every
* document as a single point (`chunk_id: "{id}#0"`), bypassing `src/transformers/`
* entirely. So it measured a different, simpler pipeline than the PoC's — an inconsistency,
* not a design choice.
*
@Walid-Azur
Walid-Azur / llm-provider-factory.ts
Created September 8, 2026 10:13
One place to build an LLM client: per-request model routing through an OpenAI-compatible gateway
// =============================================================================
// ddx-api — Dudoxx Mastra provider factory (LiteLLM-routed, per-request model)
// =============================================================================
// Dudoxx UG / Acceleate Consulting - Walid Boudabbous <walid@acceleate.com>
//
// The ONE place a Mastra LanguageModel is constructed for ddx-api. All LLM +
// embedding traffic routes through the Dudoxx LiteLLM proxy (LITELLM_BASE_URL,
// default https://llm-gateway.example.com) — a model id is NEVER hardcoded in an
// agent file. The chat default is `dudoxx-gemma` (invariant note: the CHAT
// model is NOT the embedder — the embedder is dudoxx-embed@2560, resolved
@Walid-Azur
Walid-Azur / gateway-auth.guard.ts
Created September 8, 2026 10:13
Zero-trust NestJS: HMAC gateway guard where the signed org id is proof of origin, never authorization
// =============================================================================
// ddx-api — GatewayAuthGuard (HMAC verification, BFF-only entry)
// =============================================================================
// Dudoxx UG / Acceleate Consulting - Walid Boudabbous <walid@acceleate.com>
//
// Guard chain position 2 (after ThrottlerGuard). Verifies the HMAC-signed
// X-Gateway-* header set every trusted consumer (web BFF, seeder) presents,
// keyed by a PER-CONSUMER secret (GATEWAY_API_KEY_{WEB,SEEDER}) plus the shared
// GATEWAY_SIGNING_SECRET. Rejects unsigned / tampered / replayed sets 401
// BEFORE any downstream guard runs (invariant #7).
@Walid-Azur
Walid-Azur / fhir-r4-to-r5-adapter.ts
Created September 8, 2026 10:13
FHIR R4 to R5 adapter: the five breaking resource shifts, in code
import type { FhirResource } from '../types.js';
import type { Adapter } from './types.js';
interface R4Coding {
system?: string;
code?: string;
display?: string;
version?: string;
userSelected?: boolean;
}
@Walid-Azur
Walid-Azur / fhir-conditional-upsert.ts
Created September 8, 2026 10:13
Idempotent FHIR seeding: conditional upsert for canonical resources
import type { FhirResource, SeedResult } from '../types.js';
import type { FhirHttpClient } from '../client/http.js';
import { findSeedIdentifier, identifierSearchToken } from './identifier.js';
export async function upsert(http: FhirHttpClient, resource: FhirResource): Promise<SeedResult> {
const seedId = findSeedIdentifier(resource);
if (!seedId) {
return {
resourceType: resource.resourceType,
identifier: '(missing)',