@tenderprompt/tender-app-validator
v0.1.6
Published
Validation library for Tender App source trees.
Readme
Tender App Validator
Validation library for Tender App source trees.
This package powers local CLI checks and can also be reused by Tender server paths before preview, build, Git receive, and publish work. It is a developer feedback tool, not the only security boundary. Server-side validation must still run before accepting or publishing artifact source.
Install
npm install @tenderprompt/tender-app-validatorUsage
import { validateTenderApp } from "@tenderprompt/tender-app-validator";
const result = validateTenderApp({
files: [
{
path: "app.json",
content: Buffer.from(JSON.stringify({ runtimeClass: "server_backed" })),
},
{
path: "src/server.ts",
content: Buffer.from("export default {};"),
},
],
mode: "local",
});
if (!result.ok) {
console.error(result.diagnostics);
}Validation Modes
local: local development feedback.preview: checks before preview work.publish: stricter checks before production publish work.git-receive: checks for source accepted through artifact Git.
What It Checks
- Tender App manifest shape.
edgeCorsPreflightmanifest policies for exact-path public-hosting CORS preflight acceleration.- Required project files.
- Managed environment type drift.
- TypeScript parse errors.
- suspicious outbound network usage.
- suspicious secret literals.
- forbidden repo/cache/build paths such as
.git,node_modules,dist,build,.wrangler,.turbo, and.next.
Manifest CORS Preflight Policies
Server-backed apps can opt into public-hosting edge preflight responses for known cross-origin API routes:
{
"runtimeClass": "server_backed",
"server": "src/server.ts",
"edgeCorsPreflight": [
{
"path": "/api/free-gift/current",
"allowedOrigins": ["https://example.com"],
"allowedMethods": ["POST"],
"allowedHeaders": ["content-type", "x-example-session"],
"maxAgeSeconds": 600
}
]
}Policies are exact-path declarations. They should mirror the CORS behavior in
src/server.ts; unknown routes, origins, methods, or headers stay on the normal
generated app runner path.
File Input Contract
Pass normalized source files:
type TenderAppFile = {
path: string;
content: string | Uint8Array;
};Paths should be repository-relative POSIX paths. The validator does not read from disk directly.
Security Notes
The validator is intentionally conservative. Some diagnostics are warnings for developer feedback, while errors should block preview or publish in server-side paths. Do not rely on local validation alone; Tender should still validate the artifact source on the server before build or publish.
CLI
For command-line use, install @tenderprompt/cli and run:
tender artifacts doctor --dir ./widget --json