You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Part 1 - Core refactor: unify tool/platform APIs and harden launch validation - #42
This PR delivers the core refactor for the 1.0.0 release. It unifies the top-level Tool/Platform APIs, restructures
launch validation into explicit stage-based modules, and hardens core correctness around JWT, audience, timestamps,
deployment, registration, state, and nonce validation.
This is the foundation for the follow-on Tool Deep Linking, NRPS, and AGS PRs.
What Changed
Added unified top-level APIs:
Lti_1p3.Tool.login_redirect/2
Lti_1p3.Tool.validate_launch/3
Lti_1p3.Platform.authorize_redirect/5
Refactored core validation into explicit ordered validation modules:
state
registration
JWT
timestamps
deployment
nonce
message validation
Normalized launch/auth payloads into typed structs:
%Lti_1p3.Tool.Launch{}
%Lti_1p3.Platform.AuthorizationPayload{}
Hardened audience/JWT validation and standardized deterministic error reasons
Fixed message validator naming/path consistency
Aligned provider contracts and added provider contract conformance tests
Cleaned up in-memory provider implementation drift
Added core telemetry events and integration docs
Added migration, troubleshooting, and tool/platform integration guides
Why
The existing core had correctness gaps, uneven API ergonomics, and implementation drift between behavior contracts and
runtime code. The service-specific work in later PRs depends on having a stable, spec-correct core to build on.
Reviewer Notes
Focus review on:
public API shape changes
validation pipeline correctness
provider contract consistency
security-sensitive claim/JWT handling
Service-specific deep linking / NRPS / AGS behavior is intentionally deferred to later PRs in the stack.
eliknebel
changed the title
Core refactor: unify tool/platform APIs and harden launch validation
Part 1 Core refactor: unify tool/platform APIs and harden launch validation
Mar 13, 2026
eliknebel
changed the title
Part 1 Core refactor: unify tool/platform APIs and harden launch validation
Part 1 - Core refactor: unify tool/platform APIs and harden launch validation
Mar 13, 2026
The reason will be displayed to describe this comment to others. Learn more.
It would make sense instead to simply use the harness skills from https://github.com/Simon-Initiative/harness instead of creating and adding specific, new skills here. To do that, you just need to run the $harness-bootstrap skill to create all the necessary artifacts, and then have Codex take a crack at populating them from an informal prompt.
It would make sense instead to simply use the harness skills from https://github.com/Simon-Initiative/harness instead of creating and adding specific, new skills here. To do that, you just need to run the $harness-bootstrap skill to create all the necessary artifacts, and then have Codex take a crack at populating them from an informal prompt.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR delivers the core refactor for the
1.0.0release. It unifies the top-level Tool/Platform APIs, restructureslaunch validation into explicit stage-based modules, and hardens core correctness around JWT, audience, timestamps,
deployment, registration, state, and nonce validation.
This is the foundation for the follow-on Tool Deep Linking, NRPS, and AGS PRs.
What Changed
Lti_1p3.Tool.login_redirect/2Lti_1p3.Tool.validate_launch/3Lti_1p3.Platform.authorize_redirect/5%Lti_1p3.Tool.Launch{}%Lti_1p3.Platform.AuthorizationPayload{}Why
The existing core had correctness gaps, uneven API ergonomics, and implementation drift between behavior contracts and
runtime code. The service-specific work in later PRs depends on having a stable, spec-correct core to build on.
Reviewer Notes
Focus review on:
Service-specific deep linking / NRPS / AGS behavior is intentionally deferred to later PRs in the stack.
Documentation
README.mddocs/core_tool_platform_guide.mddocs/core_migration_guide.mddocs/core_troubleshooting.mddocs/telemetry.mdCHANGELOG.md