Skip to content
 
 

Latest commit

 

History

10,807 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

🔒 This build is minidauth'd

Medusa, with a key nobody holds. Your customers, their names, phone numbers, companies and the street lines of their addresses is sealed before it ever reaches the database, encrypted with a key that is never assembled anywhere, not even to decrypt. The key lives as threshold shares across the Tide network, so the classic breach, someone walking off with your database or a backup, turns up nothing readable.

  • Your database holds only ciphertext. A stolen dump or a leaked backup is useless to whoever takes it.
  • There is no standing key to steal. The vendor key is never whole, not in this app and not on any single server.
  • Reads are governed, not assumed. A quorum grants the reading role. Revoke it and reads stop everywhere, at once.
  • Nobody juggles keys. People keep the login they already have. The gate is a role, not a keyfile they can lose.
  • Nothing else changes. Medusa works exactly as it does upstream, and sealing stays off until you turn it on.

See how it works → minidauth · dauth.me

Medusa logo

minidauth'd

Running it with minidauth

Sealing is off until you point Medusa at a minidauth sidecar; unconfigured, it behaves exactly like upstream.

  1. Bring up the backend. In a checkout of minidauth:

    cp operators.example.json operators.json
    docker compose -f docker-compose.yml -f docker-compose.seal.yml up -d
    # create a vendor key once (a licensed step; see that repo's docs/running.md)
    ./bootstrap.sh

    This runs the sealing sidecar on http://localhost:3021 and writes a signing key to ./keys/usertoken.key. Full detail: minidauth's docs/sealing.md.

  2. Point Medusa at it. Set these in its environment, then start Medusa as usual:

    MINIDAUTH_SEAL_URL=http://localhost:3021
    MINIDAUTH_SEAL_SIGNING_KEY_FILE=/absolute/path/to/minidauth/keys/usertoken.key

    Now customer names, phones, companies and address lines are sealed before they reach the database.

  3. Grant a reader. Sealed fields open only for a user the quorum granted the crm-reader role. Grant it to a staff member by their id, from the minidauth checkout:

    DEMO_UID=<staff member id> ./bootstrap.sh

    Revoke it in minidauth and their reads go dark, with no change to Medusa.

Medusa

Building blocks for digital commerce

Medusa uses an open-core licensing model. PRs welcome!

Follow @medusajs Discord Chat

Getting Started

The fastest way to get started is with Medusa Cloud. It provides a managed environment optimized for Medusa applications, with automated deployments, scaling, and maintenance. Get started on Medusa Cloud

To set up a Medusa application locally, visit the Documentation.

About Medusa

Medusa is a commerce platform with a built-in framework for customization that allows you to build custom commerce applications without reinventing core commerce logic. The framework and modules can be used to support advanced B2B or DTC commerce stores, marketplaces, distributor platforms, PoS systems, service businesses, or similar solutions that need foundational commerce primitives. Medusa's core commerce modules are open-source and freely available on npm. Enterprise Edition features are identified separately in the repository.

Learn more about Medusa’s architecture and commerce modules in the Docs.

Upgrades & Integrations

Follow the Release Notes to keep your Medusa project up-to-date.

Check out all available Medusa integrations.

Community & Contributions

The core team is available in GitHub Discussions, where you can create issues, share ideas, and discuss roadmap.

Our Contribution Guide describes how to contribute to the codebase and Docs.

Join our Discord server to meet and discuss with more than 14,000 other community members.

Other channels

License

Medusa uses an open-core model. The core is licensed under the MIT License. The RBAC-based Enterprise Edition materials identified in ENTERPRISE-LICENSE.md require a commercial agreement with MedusaJS, Inc.

About

The world's most flexible commerce platform for agents and developers

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages