mirror of
https://github.com/stablyai/orca.git
synced 2026-09-28 16:02:45 +00:00
The RpcOperation descriptor typed its params with RpcParams, which is z.output — the shape the handler receives after parsing. A field with .default(x) is required there, so a sender that legitimately omits it failed to typecheck. z.input is not the fix: the params builders parse with z.unknown() so a hostile client cannot crash the dispatcher, which collapses every requiredString/OptionalString field to `unknown`. RpcSendParams takes each channel where it is honest — key optionality from zod's own `optin` marker, value types from z.output — by walking the schema from the generated catalog, so it cannot drift from the dispatcher. 21 of 611 methods change, all by letting a sender omit a key the host already defaults. Type-level only: no runtime code, no wire change, and the params contract stays a type-only import so no client can parse a coercing schema. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb