@unciara/cougarbot-contracts
v2.4.0
Published
Client-safe runtime contracts for the Unciara CougarBot mobile app
Readme
@unciara/cougarbot-contracts
Client-safe Zod runtime schemas and inferred TypeScript types for the CougarBot mobile client.
This package is built from the canonical packages/shared-types/src/mobile.ts allowlist. Do not copy its
schemas into the mobile repository or import files outside the public package entry.
The public surface is intentionally limited to mobile authentication, entitlement, device registration, bootstrap, training-scope profile settings, offline focus packs, Fast Leopard quiz and scoring contracts, public user info cards, account feedback, recent-quiz review cards, recent mobile progress, Fast Leopard leaderboards, and the shared flip-card study data used by mobile. Web payment, admin, Discord, prompt, and server-only schemas are excluded.
The package also exposes the dormant Battle/Ghost transport and scoring contracts so Web and both native platforms can share one server-clock rule set when their UI launches.
The Product Owner selected the public npm registry and the @unciara/cougarbot-contracts package name. Local
build and pack validation do not authorize publishing it until an owner-controlled npm account confirms the
@unciara scope and the release workflow is approved.
Shared REST bindings
mobileFastLeopardContract binds the existing eight Mobile Fast Leopard operations to their HTTP
methods, complete paths, request schemas, success statuses and response schemas. Consumers supply their
existing authenticated transport; the router does not manage cookies, sessions, refresh tokens or retries.
Its metadata.retryOnUnauthorized declares whether replay is safe for each operation.
Response and entity objects strip unknown keys; request, query and path-param objects are strict. The API
only makes additive changes, so an installed App keeps working across deploys without any server-side
projection. MOBILE_CONTRACT_VERSION (sent as X-CougarBot-Contract-Version) is reserved for wire changes a
strip-tolerant client cannot absorb. Package SemVer, HTTP generation and App binary versions remain
separate axes.
The monorepo's CONTRACT_RELEASE.md documents the pinned-baseline compatibility gate and OIDC workflow.
Unpublished integrations can use a tracked tarball inside the consuming repository; production release
must return to an exact published registry version. Neither building nor staging publishes the package.
