feat!: separate provider authorizations and add safe deletion (#10)
## Summary
Separate provider credential authorization from owner-scoped DNS grants,
then add a fail-closed deletion path for records DomainKit previously
created. This establishes the consumer contract needed for isolated
multi-owner hosts without coupling DomainKit to their credential store.
## API
```ts
const { authorization, connection } = await TokenConnection.connect({
authorizationStore,
connectionStore,
credentialStore,
ownerId,
grant: { _tag: "domains", domains: [DomainName.parse("example.com")] },
// provider token and validation omitted
});
const deletionPlan = await Deletion.create({
plan: createPlan,
provider,
receipt: createReceipt,
});
const consent = await Deletion.authorize(deletionPlan);
await Deletion.apply({ authorization: consent, plan: deletionPlan, provider });
```
## Lifecycle
```text
provider account credential
-> ProviderAuthorization (shared)
-> owner A Connection + exact-zone Grant
-> owner B Connection + exact-zone Grant
detach owner A -> preserve authorization and credential
detach owner B -> provider revoke -> delete credential and authorization
```
Deletion requires a prior create receipt with a provider record ID,
exact content readback, an unexpired deletion plan, and separate
digest-bound consent. Missing or changed records fail before the first
delete; partial destructive writes return a retryable receipt.
## Breaking change
- `Connection` now contains only `ownerId`, `authorizationId`, and the
owner grant.
- OAuth and token connection flows return `{ authorization, connection
}`.
- DNS providers implement `getRecord` and `deleteRecord` for
receipt-bound cleanup.
## Validation
- `bun run release:check`
- 77 unit and provider tests
- Effect and Promise examples type-check
- packed Node, Bun, and Workers consumers pass S
Saatvik Arya committed
fcb60f49856dd11f3d26e71b1b88012a4ab40264
Parent: c31f2a3
Committed by GitHub <noreply@github.com>
on 8/28/2026, 1:13:11 PM