Summary
Strengthen the TypeScript runtime boundary around Engine authoritative state.
The current implementation declares _state with TypeScript private, which prevents ordinary typed access but is erased by the compiler. In emitted JavaScript, _state remains an ordinary reachable property. Context Compiler TS already hardens public objects through defensive copies, frozen values, and mutation-isolation tests; this issue closes the remaining direct-instance path at the JavaScript runtime level.
Architectural direction
- Replace
private _state with an ECMAScript runtime-private field such as #state.
- Ensure all enforcement and transition logic reads only the runtime-private authoritative field.
- Preserve the existing public API, conformance behavior, import/export semantics, and mutation-isolation guarantees.
- Keep public inspection surfaces as snapshots/copies rather than exposing live authoritative state.
Regression coverage
Add a built-package/runtime JavaScript test demonstrating that direct _state access cannot affect authoritative state. In particular, assigning engine._state = ... may create an unrelated public shadow property, but must not change Engine behavior or export_json() output.
Also verify the ES2022 build preserves the #state private field in emitted JavaScript.
Boundary
This is runtime encapsulation against ordinary JavaScript/TypeScript application code, not a claim of tamper resistance against arbitrary hostile code with full same-process/native privileges.
Summary
Strengthen the TypeScript runtime boundary around
Engineauthoritative state.The current implementation declares
_statewith TypeScriptprivate, which prevents ordinary typed access but is erased by the compiler. In emitted JavaScript,_stateremains an ordinary reachable property. Context Compiler TS already hardens public objects through defensive copies, frozen values, and mutation-isolation tests; this issue closes the remaining direct-instance path at the JavaScript runtime level.Architectural direction
private _statewith an ECMAScript runtime-private field such as#state.Regression coverage
Add a built-package/runtime JavaScript test demonstrating that direct
_stateaccess cannot affect authoritative state. In particular, assigningengine._state = ...may create an unrelated public shadow property, but must not change Engine behavior orexport_json()output.Also verify the ES2022 build preserves the
#stateprivate field in emitted JavaScript.Boundary
This is runtime encapsulation against ordinary JavaScript/TypeScript application code, not a claim of tamper resistance against arbitrary hostile code with full same-process/native privileges.