@symbo.ls/app-rules
v3.14.0
Published
The containment rule set for AI-generated Symbols app pages: an acorn AST audit + its rules as data, shared by the client gate and the server check
Maintainers
Keywords
Readme
@symbo.ls/app-rules
The containment rule set for AI-generated Symbols app pages, shared by the
workspace client gate and the server's write-time check. Pure ESM; acorn is
the only dependency; no DOM, no server imports.
import { auditGeneratedAppExpression, APP_EL_CALL_ALLOWLIST } from '@symbo.ls/app-rules'
const { ok, violations } = auditGeneratedAppExpression('(' + pageSource + ')', {
rootKeys, // readable s.root keys: an Array or a Set (anything else = none)
registeredComponents // the live component registry names (client only)
})
// violations: [{ rule, at, detail }] — rule names are stable (both halves report them)@symbo.ls/app-rules/rules is pure data (no imports): every list the audit
uses — the el.call allowlist, blocked members, globals, event / target /
element member allowlists, tags, markup keys, URL keys, the component
allow / deny lists.
The test suite is the shared attack corpus (core-wl's three probes, the
workspace builder cases, the server's cases): node --test __tests__/*.test.js.
Published by the release manager only.
