puffball
Import
Section titled “Import”import * as api from "@fungi.computer/puffball";Exports
Section titled “Exports”| Kind | Export | Description |
|---|---|---|
| class | AppReleaseInputError | Fixed, non-leaking input failure for one public parser boundary. |
| class | AppReleaseCommandInputError | Fixed non-leaking input failure for one public catalog command. |
| class | AppReleaseInvalidStoreResultError | Fixed non-leaking failure when a foreign Store success is structurally invalid. |
| class | AppReleaseImmutableConflictError | Fixed conflict when one Release ID receives changed immutable input. |
| class | AppReleaseOwnerAppAbsentError | Fixed failure when a new Release references an App that does not exist. |
| class | AppReleaseSurfaceOwnerAppAbsentError | Fixed failure when a new public Surface references an App that does not exist. |
| class | AppReleaseStoreUnavailableError | Fixed non-leaking failure when the injected App Release store is unavailable. |
| class | AppReleaseReleaseAbsentError | Fixed failure when artifact verification names no stored Release. |
| class | AppReleaseArtifactUnavailableError | Fixed non-leaking failure when the injected artifact reader is unavailable. |
| class | AppReleaseArtifactMissingError | Fixed failure when the requested artifact cannot be found. |
| class | AppReleaseArtifactDigestMismatchError | Fixed failure when resolved artifact bytes do not match the expected digest. |
| class | AppReleaseArtifactInvalidSnapshotError | Fixed failure when a hostile artifact read cannot form a valid snapshot. |
| class | AppReleaseUnimplementedError | Error thrown when a catalog operation is not implemented in this slice. |
| class | AppReleaseTransitionReleaseAbsentError | Fixed failure when a transition names no stored Release. |
| class | AppReleaseTransitionReleaseUnverifiedError | Fixed failure when promotion or rollback names an unverified Release. |
| class | AppReleaseTransitionArtifactIncompatibleError | Fixed failure when a website selection names a non-HTML artifact. |
| class | AppReleaseTransitionReleaseRevokedError | Fixed failure when promotion or rollback names a revoked Release. |
| class | AppReleaseTransitionSurfaceAbsentError | Fixed failure when a transition names no stored public Surface. |
| class | AppReleaseTransitionOwnershipConflictError | Fixed failure when a Release is owned by another App than its Surface. |
| class | AppReleaseTransitionIdempotencyConflictError | Fixed failure when an idempotency key is reused for changed material input. |
| class | AppReleaseTransitionIdUnavailableError | Fixed, non-leaking failure when Cairn cannot issue a transition identity. |
| class | AppReleasePublicWebsiteNotFoundError | Fixed non-leaking failure for malformed, absent, or unselected routes. |
| class | AppReleasePublicWebsiteUnavailableError | Fixed non-leaking failure when public delivery cannot be proven safe. |
| type alias | AppRole | One assignable App role. |
| type alias | AppCapabilityId | One requestable host capability id. |
| type alias | AppApi | Build-generated method metadata. This data-only projection grants no authority. |
| type alias | AppHandler | One shell navigation request an App can handle. |
| type alias | AppDeclaredCommand | One command an App declares so the backend can advertise it before the App is open: the identity, labels and projections of a Whistle definition. Availability, typed action schemas and slash argument grammars are runtime facts the mounted App registers, so they are not part of the declaration. |
| type alias | AppStorageScope | The shared Team default or the calling member’s private override. |
| type alias | AppStorageKey | One digest-covered key and the bounds its App agrees to use. |
| type alias | AppGillDesktopSize | Sizes the App explicitly offers for a desktop Gill. |
| type alias | AppDeclaredGill | A digest-covered compact view and the actions its rows may offer. |
| type alias | AppDeclaration | What an App asks of the host, covered by its Release digest. Every App, first-party or not, uses this same declaration; there is no other source. |
| type alias | AppId | Opaque Global App identifier. |
| type alias | ReleaseId | Opaque immutable Release identifier. |
| type alias | PublicSurfaceId | Opaque anonymous public-Surface identifier. |
| type alias | ArtifactRef | Opaque, bounded artifact locator for an injected reader. |
| type alias | IdempotencyKey | Caller-provided idempotency key for one control-plane operation. |
| type alias | SourceRevision | Pinned lowercase Git source revision. |
| type alias | Sha256Digest | Lowercase SHA-256 digest with its sha256: prefix. |
| type alias | StableRoute | Canonical, local origin-relative stable route for a public Surface. |
| type alias | AppTransitionId | Cairn-issued opaque identity for one owner-issued App transition. |
| type alias | ImmutableArtifactBytes | Immutable artifact bytes exposed only through fresh copies. |
| type alias | ArtifactProvenance | Source and build facts permanently bound to a Release artifact. |
| type alias | ReleaseArtifact | Immutable artifact identity and provenance bound to a Release. |
| type alias | App | Global App record owned by the catalog. |
| type alias | Release | Immutable App Release record. |
| type alias | PublicSurface | Anonymous website Surface and its explicit App owner. |
| type alias | PublicSurfacePublisher | Admitted publisher identity retained separately from public Surface metadata. |
| type alias | PublicSurfaceDefinition | Creation requires explicit publisher custody; an ID is never authority. |
| type alias | ArtifactMediaType | Supported immutable artifact representation formats. |
| type alias | VerifiedAppArtifactReference | One immutable child reference retained after App publication verification. |
| type alias | DurableBackend | Executable descriptor decoded from one verified backend child artifact. |
| type alias | VerifiedBackendProfile | Backend facts needed for admission, with executable code deliberately absent. |
| type alias | VerifiedAppDescription | Normalized immutable App description persisted by the verification owner. |
| type alias | ResolvedAppMetadata | Verified metadata returned without reading any artifact body. |
| type alias | PublicSurfaceAuthority | Current metadata-only authority for one selected public Surface. |
| type alias | VerifiedArtifactRead | Successful, verified artifact read. |
| type alias | AppUi | Verified UI representation; selection authority remains with its host. |
| type alias | AppDescription | Normalized immutable code description shared by Surface and facet consumers. |
| type alias | ResolvedApp | One eligible Release with all declared executable parts resolved. |
| type alias | ArtifactReadResult | Closed result union returned by an injected artifact reader. |
| type alias | ArtifactVerificationIntent | Names the owner-controlled verification work requested for one read. |
| type alias | ArtifactReader | Storage-neutral port that resolves an opaque reference and verifies bytes. |
| type alias | AppReleaseStoreFailure | Closed infrastructure failure projected by an App Release store. |
| type alias | AppReleaseStoreSuccess | Closed successful outcome for one App Release store operation. |
| type alias | AppReleaseStoreOperationFailure | Closed failed outcome for one App Release store operation. |
| type alias | AppReleaseStoreResult | Closed envelope returned by every App Release store operation. |
| type alias | AppRead | Explicit result of looking up one Global App. |
| type alias | AppCreate | Explicit result of atomically creating or observing one Global App. |
| type alias | ReleaseRead | Explicit result of looking up one immutable Release. |
| type alias | ReleaseCreate | Explicit result of atomically creating or observing one immutable Release. |
| type alias | PublicSurfaceRead | Explicit result of looking up one App-owned anonymous public Surface. |
| type alias | PublicSurfaceCreate | Explicit result of atomically creating or observing one public Surface. |
| type alias | ReleaseVerification | Verification fact retained after a valid immutable artifact snapshot. |
| type alias | ReleaseRevocation | Revocation fact retained independently from immutable Release bytes. |
| type alias | ReleaseLifecycle | Durable Release facts observed by transition policy. |
| type alias | PublicSurfaceLifecycle | Durable public-Surface selection fact observed by transition policy. |
| type alias | PublicWebsiteRepresentation | Safe immutable website bytes selected by the current Surface authority. |
| type alias | PublicAssetBuildRepresentation | Verified root manifest selected by the existing public Surface owner. |
| type alias | TransitionLookup | Result of looking up an operation-scoped idempotency key. |
| type alias | TransitionPersistence | Result of atomically recording one transition and its receipt. |
| type alias | PromiseAppReleaseStore | Effect-free projection of the App Release store boundary. |
| type alias | ReleaseTransition | Owner-issued transition request. |
| type alias | TransitionReceipt | Terminal receipt for an owner-issued transition. |
| type alias | AppReleaseCatalogOptions | Inputs for the catalog factory. |
| type alias | AppReleaseCatalog | Public App Release catalog and public-website resolution seam. |
| type alias | AppReleaseParserName | Names the parser boundary that rejected an untrusted value. |
| type alias | AppReleaseCommandName | Names a public catalog command whose hostile input was rejected. |
| constant | appRoles | Roles a user may assign to an App: the shell routes “open my inbox”, file
navigation, media and Session conversations to the App the Team chose.
dashboard marks an App that can open as a Team’s dashboard; the Team’s shell
selection, not a role choice, picks among them. Extend this list here; the Hub
role projection then requires the new role. |
| constant | appCapabilityIds | Host capabilities an App may request. A request is never authority; the Team’s installation grants decide. Extend this list here. |
| constant | appHandlers | Navigation requests an App can handle for the shell. |
| constant | appStorageScopes | A declared layer of the App’s own JSON data; never a cross-Team scope. |
| constant | emptyAppDeclaration | The declaration of an App that asks for nothing. |
| constant | parseAppId | Parse an opaque Global App identifier. |
| constant | parseAppTransitionId | Parse a Cairn-issued App transition identity. |
| constant | parseReleaseId | Parse an opaque immutable Release identifier. |
| constant | parsePublicSurfaceId | Parse an opaque anonymous public-Surface identifier. |
| constant | parseArtifactRef | Parse an opaque bounded artifact reference. |
| constant | parseIdempotencyKey | Parse a caller-provided idempotency key. |
| constant | parseSourceRevision | Parse a pinned lowercase Git source revision. |
| constant | parseSha256Digest | Parse a lowercase SHA-256 digest. |
| constant | parseStableRoute | Parse a canonical local origin-relative stable route. |
| function | isEmptyAppDeclaration() | An empty declaration is omitted from the manifest to keep digests stable. |
| function | issuePublicSurfaceId() | Publisher issues customer Surface identities through Cairn, never from slugs. |
| function | createAppReleaseCatalog() | Create the App Release catalog. |
AppReleaseInputErrorclass
Section titled “AppReleaseInputError”Fixed, non-leaking input failure for one public parser boundary.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseInputError(parserName): AppReleaseInputError;Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
parserName |
AppReleaseParserName |
Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructor;Properties
Section titled “Properties”parserName
Section titled “parserName”readonly parserName: AppReleaseParserName;AppReleaseCommandInputErrorclass
Section titled “AppReleaseCommandInputError”Fixed non-leaking input failure for one public catalog command.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseCommandInputError(commandName): AppReleaseCommandInputError;Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
commandName |
AppReleaseCommandName |
Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructor;Properties
Section titled “Properties”commandName
Section titled “commandName”readonly commandName: AppReleaseCommandName;AppReleaseInvalidStoreResultErrorclass
Section titled “AppReleaseInvalidStoreResultError”Fixed non-leaking failure when a foreign Store success is structurally invalid.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseInvalidStoreResultError(): AppReleaseInvalidStoreResultError;Returns
Section titled “Returns”AppReleaseInvalidStoreResultError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseImmutableConflictErrorclass
Section titled “AppReleaseImmutableConflictError”Fixed conflict when one Release ID receives changed immutable input.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseImmutableConflictError(): AppReleaseImmutableConflictError;Returns
Section titled “Returns”AppReleaseImmutableConflictError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseOwnerAppAbsentErrorclass
Section titled “AppReleaseOwnerAppAbsentError”Fixed failure when a new Release references an App that does not exist.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseOwnerAppAbsentError(appId): AppReleaseOwnerAppAbsentError;Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
appId |
AppId |
Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructor;Properties
Section titled “Properties”readonly appId: AppId;AppReleaseSurfaceOwnerAppAbsentErrorclass
Section titled “AppReleaseSurfaceOwnerAppAbsentError”Fixed failure when a new public Surface references an App that does not exist.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseSurfaceOwnerAppAbsentError(appId): AppReleaseSurfaceOwnerAppAbsentError;Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
appId |
AppId |
Returns
Section titled “Returns”AppReleaseSurfaceOwnerAppAbsentError
Overrides
Section titled “Overrides”Error.constructor;Properties
Section titled “Properties”readonly appId: AppId;AppReleaseStoreUnavailableErrorclass
Section titled “AppReleaseStoreUnavailableError”Fixed non-leaking failure when the injected App Release store is unavailable.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseStoreUnavailableError(): AppReleaseStoreUnavailableError;Returns
Section titled “Returns”AppReleaseStoreUnavailableError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseReleaseAbsentErrorclass
Section titled “AppReleaseReleaseAbsentError”Fixed failure when artifact verification names no stored Release.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseReleaseAbsentError(): AppReleaseReleaseAbsentError;Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructor;AppReleaseArtifactUnavailableErrorclass
Section titled “AppReleaseArtifactUnavailableError”Fixed non-leaking failure when the injected artifact reader is unavailable.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseArtifactUnavailableError(): AppReleaseArtifactUnavailableError;Returns
Section titled “Returns”AppReleaseArtifactUnavailableError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseArtifactMissingErrorclass
Section titled “AppReleaseArtifactMissingError”Fixed failure when the requested artifact cannot be found.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseArtifactMissingError(): AppReleaseArtifactMissingError;Returns
Section titled “Returns”AppReleaseArtifactMissingError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseArtifactDigestMismatchErrorclass
Section titled “AppReleaseArtifactDigestMismatchError”Fixed failure when resolved artifact bytes do not match the expected digest.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseArtifactDigestMismatchError(): AppReleaseArtifactDigestMismatchError;Returns
Section titled “Returns”AppReleaseArtifactDigestMismatchError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseArtifactInvalidSnapshotErrorclass
Section titled “AppReleaseArtifactInvalidSnapshotError”Fixed failure when a hostile artifact read cannot form a valid snapshot.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseArtifactInvalidSnapshotError(): AppReleaseArtifactInvalidSnapshotError;Returns
Section titled “Returns”AppReleaseArtifactInvalidSnapshotError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseUnimplementedErrorclass
Section titled “AppReleaseUnimplementedError”Error thrown when a catalog operation is not implemented in this slice.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseUnimplementedError(): AppReleaseUnimplementedError;Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructor;AppReleaseTransitionReleaseAbsentErrorclass
Section titled “AppReleaseTransitionReleaseAbsentError”Fixed failure when a transition names no stored Release.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseTransitionReleaseAbsentError(): AppReleaseTransitionReleaseAbsentError;Returns
Section titled “Returns”AppReleaseTransitionReleaseAbsentError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseTransitionReleaseUnverifiedErrorclass
Section titled “AppReleaseTransitionReleaseUnverifiedError”Fixed failure when promotion or rollback names an unverified Release.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseTransitionReleaseUnverifiedError(): AppReleaseTransitionReleaseUnverifiedError;Returns
Section titled “Returns”AppReleaseTransitionReleaseUnverifiedError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseTransitionArtifactIncompatibleErrorclass
Section titled “AppReleaseTransitionArtifactIncompatibleError”Fixed failure when a website selection names a non-HTML artifact.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseTransitionArtifactIncompatibleError(): AppReleaseTransitionArtifactIncompatibleError;Returns
Section titled “Returns”AppReleaseTransitionArtifactIncompatibleError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseTransitionReleaseRevokedErrorclass
Section titled “AppReleaseTransitionReleaseRevokedError”Fixed failure when promotion or rollback names a revoked Release.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseTransitionReleaseRevokedError(): AppReleaseTransitionReleaseRevokedError;Returns
Section titled “Returns”AppReleaseTransitionReleaseRevokedError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseTransitionSurfaceAbsentErrorclass
Section titled “AppReleaseTransitionSurfaceAbsentError”Fixed failure when a transition names no stored public Surface.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseTransitionSurfaceAbsentError(): AppReleaseTransitionSurfaceAbsentError;Returns
Section titled “Returns”AppReleaseTransitionSurfaceAbsentError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseTransitionOwnershipConflictErrorclass
Section titled “AppReleaseTransitionOwnershipConflictError”Fixed failure when a Release is owned by another App than its Surface.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseTransitionOwnershipConflictError(): AppReleaseTransitionOwnershipConflictError;Returns
Section titled “Returns”AppReleaseTransitionOwnershipConflictError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseTransitionIdempotencyConflictErrorclass
Section titled “AppReleaseTransitionIdempotencyConflictError”Fixed failure when an idempotency key is reused for changed material input.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseTransitionIdempotencyConflictError(): AppReleaseTransitionIdempotencyConflictError;Returns
Section titled “Returns”AppReleaseTransitionIdempotencyConflictError
Overrides
Section titled “Overrides”Error.constructor;AppReleaseTransitionIdUnavailableErrorclass
Section titled “AppReleaseTransitionIdUnavailableError”Fixed, non-leaking failure when Cairn cannot issue a transition identity.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleaseTransitionIdUnavailableError(): AppReleaseTransitionIdUnavailableError;Returns
Section titled “Returns”AppReleaseTransitionIdUnavailableError
Overrides
Section titled “Overrides”Error.constructor;AppReleasePublicWebsiteNotFoundErrorclass
Section titled “AppReleasePublicWebsiteNotFoundError”Fixed non-leaking failure for malformed, absent, or unselected routes.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleasePublicWebsiteNotFoundError(): AppReleasePublicWebsiteNotFoundError;Returns
Section titled “Returns”AppReleasePublicWebsiteNotFoundError
Overrides
Section titled “Overrides”Error.constructor;AppReleasePublicWebsiteUnavailableErrorclass
Section titled “AppReleasePublicWebsiteUnavailableError”Fixed non-leaking failure when public delivery cannot be proven safe.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new AppReleasePublicWebsiteUnavailableError(): AppReleasePublicWebsiteUnavailableError;Returns
Section titled “Returns”AppReleasePublicWebsiteUnavailableError
Overrides
Section titled “Overrides”Error.constructor;AppRoletype alias
Section titled “AppRole”type AppRole = (typeof appRoles)[number];One assignable App role.
AppCapabilityIdtype alias
Section titled “AppCapabilityId”type AppCapabilityId = (typeof appCapabilityIds)[number];One requestable host capability id.
AppApitype alias
Section titled “AppApi”type AppApi = Readonly<{ methods: Readonly< Record< string, Readonly<{ description: string; input: object; output: object; effect: "read" | "write" | "external"; requires: readonly AppCapabilityId[]; }> > >;}>;Build-generated method metadata. This data-only projection grants no authority.
AppHandlertype alias
Section titled “AppHandler”type AppHandler = (typeof appHandlers)[number];One shell navigation request an App can handle.
AppDeclaredCommandtype alias
Section titled “AppDeclaredCommand”type AppDeclaredCommand = Readonly<{ id: string; title: string; category: string; description?: string; sigil?: string; projections?: Readonly<{ bindings?: Readonly<{ order?: ... | ...; }> & Readonly<{ values: readonly ...; }>; agent?: Readonly<{ order?: ... | ...; }> & Readonly<{ keybind?: ... | ...; }>; help?: Readonly<{ order?: number; }>; menu?: Readonly<{ order?: number; }>; palette?: Readonly<{ order?: number; }>; slash?: Readonly<{ order?: ... | ...; }> & Readonly<{ aliases: readonly ...; }>; }>;}>;One command an App declares so the backend can advertise it before the App is open: the identity, labels and projections of a Whistle definition. Availability, typed action schemas and slash argument grammars are runtime facts the mounted App registers, so they are not part of the declaration.
AppStorageScopetype alias
Section titled “AppStorageScope”type AppStorageScope = (typeof appStorageScopes)[number];The shared Team default or the calling member’s private override.
AppStorageKeytype alias
Section titled “AppStorageKey”type AppStorageKey = Readonly<{ key: string; scopes: readonly AppStorageScope[]; maxBytes: number;}>;One digest-covered key and the bounds its App agrees to use.
AppGillDesktopSizetype alias
Section titled “AppGillDesktopSize”type AppGillDesktopSize = "S" | "M" | "L";Sizes the App explicitly offers for a desktop Gill.
AppDeclaredGilltype alias
Section titled “AppDeclaredGill”type AppDeclaredGill = Readonly<{ id: string; resource: "agent.sessions.inbox"; title: string; actions?: readonly Readonly<{ id: string; title: string; }>[]; desktop?: Readonly<{ sizes: readonly AppGillDesktopSize[]; }>;}>;A digest-covered compact view and the actions its rows may offer.
AppDeclarationtype alias
Section titled “AppDeclaration”type AppDeclaration = Readonly<{ api?: AppApi; displayName?: string; capabilities: readonly AppCapabilityId[]; guidance?: string; handlers: readonly AppHandler[]; icon?: string; roles: readonly AppRole[]; storage?: readonly AppStorageKey[]; commands?: readonly AppDeclaredCommand[]; gills?: readonly AppDeclaredGill[]; backend?: Readonly<{ bindings: readonly AppBackendBinding[]; }>;}>;What an App asks of the host, covered by its Release digest. Every App, first-party or not, uses this same declaration; there is no other source.
AppIdtype alias
Section titled “AppId”type AppId = string & object;Opaque Global App identifier.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
appReleaseKind |
"AppId" |
ReleaseIdtype alias
Section titled “ReleaseId”type ReleaseId = string & object;Opaque immutable Release identifier.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
appReleaseKind |
"ReleaseId" |
PublicSurfaceIdtype alias
Section titled “PublicSurfaceId”type PublicSurfaceId = string & object;Opaque anonymous public-Surface identifier.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
appReleaseKind |
"PublicSurfaceId" |
ArtifactReftype alias
Section titled “ArtifactRef”type ArtifactRef = string & object;Opaque, bounded artifact locator for an injected reader.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
appReleaseKind |
"ArtifactRef" |
IdempotencyKeytype alias
Section titled “IdempotencyKey”type IdempotencyKey = string & object;Caller-provided idempotency key for one control-plane operation.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
appReleaseKind |
"IdempotencyKey" |
SourceRevisiontype alias
Section titled “SourceRevision”type SourceRevision = string & object;Pinned lowercase Git source revision.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
appReleaseKind |
"SourceRevision" |
Sha256Digesttype alias
Section titled “Sha256Digest”type Sha256Digest = string & object;Lowercase SHA-256 digest with its sha256: prefix.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
appReleaseKind |
"Sha256Digest" |
StableRoutetype alias
Section titled “StableRoute”type StableRoute = string & object;Canonical, local origin-relative stable route for a public Surface.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
appReleaseKind |
"StableRoute" |
AppTransitionIdtype alias
Section titled “AppTransitionId”type AppTransitionId = CairnId<"app-release", "transition">;Cairn-issued opaque identity for one owner-issued App transition.
ImmutableArtifactBytestype alias
Section titled “ImmutableArtifactBytes”type ImmutableArtifactBytes = object;Immutable artifact bytes exposed only through fresh copies.
Properties
Section titled “Properties”byteLength
Section titled “byteLength”readonly byteLength: number;The immutable snapshot’s bounded byte length.
Methods
Section titled “Methods”copy()
Section titled “copy()”copy(): Uint8Array;Return an independently mutable copy of the immutable snapshot.
Returns
Section titled “Returns”Uint8Array
ArtifactProvenancetype alias
Section titled “ArtifactProvenance”type ArtifactProvenance = object;Source and build facts permanently bound to a Release artifact.
Properties
Section titled “Properties”sourceRevision
Section titled “sourceRevision”readonly sourceRevision: SourceRevision;Pinned source revision from which the artifact was built.
sourceTreeDigest
Section titled “sourceTreeDigest”readonly sourceTreeDigest: Sha256Digest;Digest of the source tree used for the build.
buildRecipeDigest
Section titled “buildRecipeDigest”readonly buildRecipeDigest: Sha256Digest;Digest of the deterministic build recipe.
ReleaseArtifacttype alias
Section titled “ReleaseArtifact”type ReleaseArtifact = object;Immutable artifact identity and provenance bound to a Release.
Properties
Section titled “Properties”artifactRef
Section titled “artifactRef”readonly artifactRef: ArtifactRef;Opaque reference resolved only by the injected reader.
artifactDigest
Section titled “artifactDigest”readonly artifactDigest: Sha256Digest;Digest expected from the resolved artifact bytes.
provenance
Section titled “provenance”readonly provenance: ArtifactProvenance;Write-once source and build provenance.
Apptype alias
Section titled “App”type App = object;Global App record owned by the catalog.
Properties
Section titled “Properties”readonly appId: AppId;Opaque App identity.
Releasetype alias
Section titled “Release”type Release = object;Immutable App Release record.
Properties
Section titled “Properties”releaseId
Section titled “releaseId”readonly releaseId: ReleaseId;Opaque immutable Release identity.
readonly appId: AppId;App that owns this Release.
artifact
Section titled “artifact”readonly artifact: ReleaseArtifact;Immutable artifact identity and provenance.
PublicSurfacetype alias
Section titled “PublicSurface”type PublicSurface = object;Anonymous website Surface and its explicit App owner.
Properties
Section titled “Properties”publicSurfaceId
Section titled “publicSurfaceId”readonly publicSurfaceId: PublicSurfaceId;Opaque public-Surface identity.
readonly appId: AppId;App that owns this Surface.
stableRoute
Section titled “stableRoute”readonly stableRoute: StableRoute;Canonical local route locator for this Surface.
PublicSurfacePublishertype alias
Section titled “PublicSurfacePublisher”type PublicSurfacePublisher = Readonly<{ kind: "customer" | "platform"; teamId: string; userId: string; requestKey: string;}>;Admitted publisher identity retained separately from public Surface metadata.
PublicSurfaceDefinitiontype alias
Section titled “PublicSurfaceDefinition”type PublicSurfaceDefinition = PublicSurface & Readonly<{ publisher: PublicSurfacePublisher; }>;Creation requires explicit publisher custody; an ID is never authority.
ArtifactMediaTypetype alias
Section titled “ArtifactMediaType”type ArtifactMediaType = | "text/html; charset=utf-8" | "application/vnd.fungi.app-backend+json" | "application/vnd.fungi.app-assets+json" | "application/vnd.fungi.app+json";Supported immutable artifact representation formats.
VerifiedAppArtifactReferencetype alias
Section titled “VerifiedAppArtifactReference”type VerifiedAppArtifactReference = Readonly<{ artifactRef: ArtifactRef; digest: Sha256Digest; mediaType: Exclude<ArtifactMediaType, "application/vnd.fungi.app+json">; version: string; byteLength: number;}>;One immutable child reference retained after App publication verification.
DurableBackendtype alias
Section titled “DurableBackend”type DurableBackend = Readonly<{ runtime: Readonly<{ kind: "durable-facet"; stateSchema: number; }>; compatibilityDate: string; exportName: string; code: string;}>;Executable descriptor decoded from one verified backend child artifact.
VerifiedBackendProfiletype alias
Section titled “VerifiedBackendProfile”type VerifiedBackendProfile = Omit<DurableBackend, "code">;Backend facts needed for admission, with executable code deliberately absent.
VerifiedAppDescriptiontype alias
Section titled “VerifiedAppDescription”type VerifiedAppDescription = Readonly<{ format: "fungi-app-v1"; ui: VerifiedAppArtifactReference | null; backend: Readonly<{ artifact: VerifiedAppArtifactReference; profile: VerifiedBackendProfile; }> | null; declaration: AppDeclaration;}>;Normalized immutable App description persisted by the verification owner.
ResolvedAppMetadatatype alias
Section titled “ResolvedAppMetadata”type ResolvedAppMetadata = Readonly<{ release: Release; digest: Sha256Digest; description: VerifiedAppDescription;}>;Verified metadata returned without reading any artifact body.
PublicSurfaceAuthoritytype alias
Section titled “PublicSurfaceAuthority”type PublicSurfaceAuthority = Readonly<{ currentReleaseId: ReleaseId; sequence: number; app: App; release: Release; surface: PublicSurface; digest: Sha256Digest; revocation: ReleaseRevocation; description: VerifiedAppDescription;}>;Current metadata-only authority for one selected public Surface.
VerifiedArtifactReadtype alias
Section titled “VerifiedArtifactRead”type VerifiedArtifactRead = object;Successful, verified artifact read.
Properties
Section titled “Properties”readonly kind: "verified";Discriminant for a verified immutable representation snapshot.
digest
Section titled “digest”readonly digest: Sha256Digest;Computed digest matching the requested digest.
mediaType
Section titled “mediaType”readonly mediaType: ArtifactMediaType;Explicit artifact formats; an asset root is never interpreted as HTML or backend code.
readonly bytes: ImmutableArtifactBytes;Immutable representation byte snapshot.
byteLength
Section titled “byteLength”readonly byteLength: number;Byte length matching the immutable snapshot.
AppUitype alias
Section titled “AppUi”type AppUi = Omit<VerifiedArtifactRead, "kind" | "mediaType"> & object;Verified UI representation; selection authority remains with its host.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
mediaType |
"text/html; charset=utf-8" | "application/vnd.fungi.app-assets+json" |
AppDescriptiontype alias
Section titled “AppDescription”type AppDescription = Readonly<{ ui: AppUi | null; backend: Readonly<{ digest: Sha256Digest; descriptor: DurableBackend; }> | null;}>;Normalized immutable code description shared by Surface and facet consumers.
ResolvedApptype alias
Section titled “ResolvedApp”type ResolvedApp = AppDescription & Readonly<{ release: Release; digest: Sha256Digest; }>;One eligible Release with all declared executable parts resolved.
ArtifactReadResulttype alias
Section titled “ArtifactReadResult”type ArtifactReadResult = | VerifiedArtifactRead | { kind: "unavailable"; } | { kind: "missing"; } | { kind: "digest-mismatch"; actualDigest: Sha256Digest; };Closed result union returned by an injected artifact reader.
ArtifactVerificationIntenttype alias
Section titled “ArtifactVerificationIntent”type ArtifactVerificationIntent = "publication";Names the owner-controlled verification work requested for one read.
ArtifactReadertype alias
Section titled “ArtifactReader”type ArtifactReader = object;Storage-neutral port that resolves an opaque reference and verifies bytes.
Methods
Section titled “Methods”read()
Section titled “read()”read(input): Promise<ArtifactReadResult>;Resolve and verify exactly one expected immutable artifact.
Parameters
Section titled “Parameters”| Parameter | Type | Description |
|---|---|---|
input |
{ artifactRef: ArtifactRef; expectedDigest: Sha256Digest; expectedObject?: { version: string; byteLength: number; }; verification?: ArtifactVerificationIntent; } |
- |
input.artifactRef |
ArtifactRef |
Opaque artifact reference; never a storage capability. |
input.expectedDigest |
Sha256Digest |
Digest that the resolved bytes must match. |
input.expectedObject? |
{ version: string; byteLength: number; } |
Child reference pins the native object version as well as its content. |
input.expectedObject.version |
string |
- |
input.expectedObject.byteLength |
number |
- |
input.verification? |
ArtifactVerificationIntent |
Publication asks the reader to verify every object named by an asset manifest. Omitted for ordinary delivery, which verifies one requested object at the asset handler boundary. |
Returns
Section titled “Returns”Promise<ArtifactReadResult>
AppReleaseStoreFailuretype alias
Section titled “AppReleaseStoreFailure”type AppReleaseStoreFailure = object;Closed infrastructure failure projected by an App Release store.
Properties
Section titled “Properties”readonly kind: "unavailable";AppReleaseStoreSuccesstype alias
Section titled “AppReleaseStoreSuccess”type AppReleaseStoreSuccess<Value> = object;Closed successful outcome for one App Release store operation.
Type Parameters
Section titled “Type Parameters”| Type Parameter |
|---|
Value |
Properties
Section titled “Properties”readonly kind: "success";readonly value: Value;AppReleaseStoreOperationFailuretype alias
Section titled “AppReleaseStoreOperationFailure”type AppReleaseStoreOperationFailure = object;Closed failed outcome for one App Release store operation.
Properties
Section titled “Properties”readonly kind: "failure";failure
Section titled “failure”readonly failure: AppReleaseStoreFailure;AppReleaseStoreResulttype alias
Section titled “AppReleaseStoreResult”type AppReleaseStoreResult<Value> = AppReleaseStoreSuccess<Value> | AppReleaseStoreOperationFailure;Closed envelope returned by every App Release store operation.
Type Parameters
Section titled “Type Parameters”| Type Parameter |
|---|
Value |
AppReadtype alias
Section titled “AppRead”type AppRead = | { kind: "found"; app: App; } | { kind: "absent"; };Explicit result of looking up one Global App.
AppCreatetype alias
Section titled “AppCreate”type AppCreate = | { kind: "created"; app: App; } | { kind: "existing"; app: App; };Explicit result of atomically creating or observing one Global App.
ReleaseReadtype alias
Section titled “ReleaseRead”type ReleaseRead = | { kind: "found"; release: Release; } | { kind: "absent"; };Explicit result of looking up one immutable Release.
ReleaseCreatetype alias
Section titled “ReleaseCreate”type ReleaseCreate = | { kind: "created"; release: Release; } | { kind: "existing"; release: Release; };Explicit result of atomically creating or observing one immutable Release.
PublicSurfaceReadtype alias
Section titled “PublicSurfaceRead”type PublicSurfaceRead = | { kind: "found"; surface: PublicSurface; } | { kind: "absent"; };Explicit result of looking up one App-owned anonymous public Surface.
PublicSurfaceCreatetype alias
Section titled “PublicSurfaceCreate”type PublicSurfaceCreate = | { kind: "created"; surface: PublicSurface; } | { kind: "existing"; surface: PublicSurface; } | { kind: "conflict"; };Explicit result of atomically creating or observing one public Surface.
ReleaseVerificationtype alias
Section titled “ReleaseVerification”type ReleaseVerification = | { kind: "verified"; digest: Sha256Digest; mediaType: "application/vnd.fungi.app+json"; description: VerifiedAppDescription; } | { kind: "unverified"; };Verification fact retained after a valid immutable artifact snapshot.
ReleaseRevocationtype alias
Section titled “ReleaseRevocation”type ReleaseRevocation = | { kind: "active"; } | { kind: "revoked"; };Revocation fact retained independently from immutable Release bytes.
ReleaseLifecycletype alias
Section titled “ReleaseLifecycle”type ReleaseLifecycle = | { kind: "found"; release: Release; verification: ReleaseVerification; revocation: ReleaseRevocation; } | { kind: "absent"; };Durable Release facts observed by transition policy.
PublicSurfaceLifecycletype alias
Section titled “PublicSurfaceLifecycle”type PublicSurfaceLifecycle = | { kind: "found"; surface: PublicSurface; selection: | { kind: "none"; } | { kind: "selected"; releaseId: ReleaseId; }; } | { kind: "absent"; };Durable public-Surface selection fact observed by transition policy.
PublicWebsiteRepresentationtype alias
Section titled “PublicWebsiteRepresentation”type PublicWebsiteRepresentation = Readonly<{ releaseId: ReleaseId; digest: Sha256Digest; mediaType: "text/html; charset=utf-8"; byteLength: number; bytes: ImmutableArtifactBytes;}>;Safe immutable website bytes selected by the current Surface authority.
PublicAssetBuildRepresentationtype alias
Section titled “PublicAssetBuildRepresentation”type PublicAssetBuildRepresentation = Omit< PublicWebsiteRepresentation, "mediaType"> & object;Verified root manifest selected by the existing public Surface owner.
Type Declaration
Section titled “Type Declaration”| Name | Type |
|---|---|
mediaType |
"application/vnd.fungi.app-assets+json" |
TransitionLookuptype alias
Section titled “TransitionLookup”type TransitionLookup = | { kind: "absent"; } | { kind: "found"; receipt: TransitionReceipt; } | { kind: "conflict"; };Result of looking up an operation-scoped idempotency key.
TransitionPersistencetype alias
Section titled “TransitionPersistence”type TransitionPersistence = | { kind: "created"; receipt: TransitionReceipt; } | { kind: "existing"; receipt: TransitionReceipt; } | { kind: "conflict"; } | { kind: "identity-collision"; } | { kind: "lifecycle-conflict"; };Result of atomically recording one transition and its receipt.
PromiseAppReleaseStoretype alias
Section titled “PromiseAppReleaseStore”type PromiseAppReleaseStore = object;Effect-free projection of the App Release store boundary.
Properties
Section titled “Properties”readReleaseLifecycle?
Section titled “readReleaseLifecycle?”readonly optional readReleaseLifecycle?: (releaseId) => Promise<AppReleaseStoreResult<ReleaseLifecycle>>;Read immutable Release facts needed by owner-issued transitions.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<ReleaseLifecycle>>
recordReleaseVerification?
Section titled “recordReleaseVerification?”readonly optional recordReleaseVerification?: (input) => Promise<AppReleaseStoreResult<{ kind: "recorded";}>>;Atomically retain that one Release artifact was successfully verified.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
{ releaseId: ReleaseId; digest: Sha256Digest; mediaType: "application/vnd.fungi.app+json"; description: VerifiedAppDescription; } |
input.releaseId |
ReleaseId |
input.digest |
Sha256Digest |
input.mediaType |
"application/vnd.fungi.app+json" |
input.description |
VerifiedAppDescription |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<{ kind:
"recorded"; }>>
readTransition?
Section titled “readTransition?”readonly optional readTransition?: (request) => Promise<AppReleaseStoreResult<TransitionLookup>>;Read one operation-scoped transition receipt before policy checks.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
request |
ReleaseTransition |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<TransitionLookup>>
persistTransition?
Section titled “persistTransition?”readonly optional persistTransition?: (request, receipt) => Promise<AppReleaseStoreResult<TransitionPersistence>>;Atomically persist a validated transition and its terminal receipt.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
request |
ReleaseTransition |
receipt |
TransitionReceipt |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<TransitionPersistence>>
Methods
Section titled “Methods”readApp()
Section titled “readApp()”readApp(appId): Promise<AppReleaseStoreResult<AppRead>>;Look up one App by its opaque identifier.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
appId |
AppId |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<AppRead>>
createAppIfAbsent()
Section titled “createAppIfAbsent()”createAppIfAbsent(app): Promise<AppReleaseStoreResult<AppCreate>>;Create an App if absent, or return the immutable existing record.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
app |
App |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<AppCreate>>
readRelease()
Section titled “readRelease()”readRelease(releaseId): Promise<AppReleaseStoreResult<ReleaseRead>>;Look up one immutable Release by its opaque identifier.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<ReleaseRead>>
createReleaseIfAbsent()
Section titled “createReleaseIfAbsent()”createReleaseIfAbsent(release): Promise<AppReleaseStoreResult<ReleaseCreate>>;Create a Release if absent, or return the immutable existing record.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
release |
Release |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<ReleaseCreate>>
readPublicSurface()
Section titled “readPublicSurface()”readPublicSurface(publicSurfaceId): Promise<AppReleaseStoreResult<PublicSurfaceRead>>;Look up one public Surface by its opaque identifier.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
publicSurfaceId |
PublicSurfaceId |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<PublicSurfaceRead>>
createPublicSurfaceIfAbsent()
Section titled “createPublicSurfaceIfAbsent()”createPublicSurfaceIfAbsent(surface): Promise<AppReleaseStoreResult<PublicSurfaceCreate>>;Create a public Surface if absent, or return the immutable existing record.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
surface |
PublicSurfaceDefinition |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<PublicSurfaceCreate>>
ReleaseTransitiontype alias
Section titled “ReleaseTransition”type ReleaseTransition = | { kind: "promotion"; publicSurfaceId: PublicSurfaceId; releaseId: ReleaseId; idempotencyKey: IdempotencyKey; } | { kind: "rollback"; publicSurfaceId: PublicSurfaceId; releaseId: ReleaseId; idempotencyKey: IdempotencyKey; } | { kind: "revocation"; releaseId: ReleaseId; idempotencyKey: IdempotencyKey; };Owner-issued transition request.
TransitionReceipttype alias
Section titled “TransitionReceipt”type TransitionReceipt = object;Terminal receipt for an owner-issued transition.
Properties
Section titled “Properties”transition
Section titled “transition”readonly transition: ReleaseTransition;transitionId
Section titled “transitionId”readonly transitionId: AppTransitionId;AppReleaseCatalogOptionstype alias
Section titled “AppReleaseCatalogOptions”type AppReleaseCatalogOptions = object;Inputs for the catalog factory.
Properties
Section titled “Properties”artifactReader
Section titled “artifactReader”readonly artifactReader: ArtifactReader;readonly store: PromiseAppReleaseStore;artifactPolicy?
Section titled “artifactPolicy?”readonly optional artifactPolicy?: object;maxBytes
Section titled “maxBytes”readonly maxBytes: number;maxManifestBytes?
Section titled “maxManifestBytes?”readonly optional maxManifestBytes?: number;AppReleaseCatalogtype alias
Section titled “AppReleaseCatalog”type AppReleaseCatalog = object;Public App Release catalog and public-website resolution seam.
Methods
Section titled “Methods”createApp()
Section titled “createApp()”createApp(app): Promise<App>;Create an App once and return the canonical stored record.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
app |
App |
Returns
Section titled “Returns”Promise<App>
createRelease()
Section titled “createRelease()”createRelease(release): Promise<Release>;Create a Release once and return the canonical stored record.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
release |
Release |
Returns
Section titled “Returns”Promise<Release>
verifyReleaseArtifact()
Section titled “verifyReleaseArtifact()”verifyReleaseArtifact(releaseId): Promise<VerifiedArtifactRead>;Resolve and verify the immutable artifact bound to a Release.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<VerifiedArtifactRead>
resolveEligibleReleaseArtifact()
Section titled “resolveEligibleReleaseArtifact()”resolveEligibleReleaseArtifact(releaseId): Promise<VerifiedArtifactRead & object>;Read one verified, active Release snapshot and recheck its lifecycle. The caller owns selection authorization and must resolve before each use.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<VerifiedArtifactRead & object>
resolveEligibleApp()
Section titled “resolveEligibleApp()”resolveEligibleApp(releaseId): Promise<ResolvedApp>;Resolve the UI and backend bound by one eligible immutable Release.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<ResolvedApp>
resolveEligibleAppMetadata()
Section titled “resolveEligibleAppMetadata()”resolveEligibleAppMetadata(releaseId): Promise<Readonly<{ release: Release; digest: Sha256Digest; description: VerifiedAppDescription;}>>;Resolve verified App metadata without reading any artifact body.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<Readonly<{ release: Release; digest:
Sha256Digest; description:
VerifiedAppDescription; }>>
resolvePublicSurfaceAuthority()
Section titled “resolvePublicSurfaceAuthority()”resolvePublicSurfaceAuthority(stableRoute): Promise<Readonly<{ currentReleaseId: ReleaseId; sequence: number; app: App; release: Release; surface: PublicSurface; digest: Sha256Digest; revocation: ReleaseRevocation; description: VerifiedAppDescription;}>>;Resolve one selected Surface’s current metadata authority without bodies.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
stableRoute |
StableRoute |
Returns
Section titled “Returns”Promise<Readonly<{ currentReleaseId: ReleaseId;
sequence: number; app: App; release: Release;
surface: PublicSurface; digest:
Sha256Digest; revocation:
ReleaseRevocation; description:
VerifiedAppDescription; }>>
resolvePublicSurfaceAuthorityVersion()
Section titled “resolvePublicSurfaceAuthorityVersion()”resolvePublicSurfaceAuthorityVersion(stableRoute, releaseId): Promise<Readonly<{ currentReleaseId: ReleaseId; sequence: number; app: App; release: Release; surface: PublicSurface; digest: Sha256Digest; revocation: ReleaseRevocation; description: VerifiedAppDescription;}>>;Resolve one previously selected Release’s current metadata authority.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
stableRoute |
StableRoute |
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<Readonly<{ currentReleaseId: ReleaseId;
sequence: number; app: App; release: Release;
surface: PublicSurface; digest:
Sha256Digest; revocation:
ReleaseRevocation; description:
VerifiedAppDescription; }>>
createPublicSurface()
Section titled “createPublicSurface()”createPublicSurface(surface): Promise<PublicSurface>;Create a public Surface once and return the canonical stored record.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
surface |
PublicSurfaceDefinition |
Returns
Section titled “Returns”Promise<PublicSurface>
transition()
Section titled “transition()”transition(request): Promise<TransitionReceipt>;Apply one owner-issued promotion, rollback, or revocation request.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
request |
ReleaseTransition |
Returns
Section titled “Returns”Promise<TransitionReceipt>
resolvePublicAssetBuild()
Section titled “resolvePublicAssetBuild()”resolvePublicAssetBuild(stableRoute): Promise<PublicAssetBuildRepresentation>;Resolve an asset-build root through the same current Surface authority.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
stableRoute |
StableRoute |
Returns
Section titled “Returns”Promise<PublicAssetBuildRepresentation>
resolvePublicAssetBuildVersion()
Section titled “resolvePublicAssetBuildVersion()”resolvePublicAssetBuildVersion(stableRoute, releaseId): Promise<PublicAssetBuildRepresentation>;Resolve a pinned asset-build root through Surface authority.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
stableRoute |
StableRoute |
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<PublicAssetBuildRepresentation>
resolvePublicWebsite()
Section titled “resolvePublicWebsite()”resolvePublicWebsite(stableRoute): Promise<Readonly<{ releaseId: ReleaseId; digest: Sha256Digest; mediaType: "text/html; charset=utf-8"; byteLength: number; bytes: ImmutableArtifactBytes;}>>;Resolve the current eligible immutable website representation.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
stableRoute |
StableRoute |
Returns
Section titled “Returns”Promise<Readonly<{ releaseId: ReleaseId; digest:
Sha256Digest; mediaType: "text/html; charset=utf-8";
byteLength: number; bytes:
ImmutableArtifactBytes; }>>
resolvePublicWebsiteVersion()
Section titled “resolvePublicWebsiteVersion()”resolvePublicWebsiteVersion(stableRoute, releaseId): Promise<Readonly<{ releaseId: ReleaseId; digest: Sha256Digest; mediaType: "text/html; charset=utf-8"; byteLength: number; bytes: ImmutableArtifactBytes;}>>;Resolve a pinned eligible immutable website representation.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
stableRoute |
StableRoute |
releaseId |
ReleaseId |
Returns
Section titled “Returns”Promise<Readonly<{ releaseId: ReleaseId; digest:
Sha256Digest; mediaType: "text/html; charset=utf-8";
byteLength: number; bytes:
ImmutableArtifactBytes; }>>
AppReleaseParserNametype alias
Section titled “AppReleaseParserName”type AppReleaseParserName = | "AppId" | "ReleaseId" | "PublicSurfaceId" | "ArtifactRef" | "IdempotencyKey" | "SourceRevision" | "Sha256Digest" | "StableRoute" | "AppTransitionId";Names the parser boundary that rejected an untrusted value.
AppReleaseCommandNametype alias
Section titled “AppReleaseCommandName”type AppReleaseCommandName = | "createApp" | "createRelease" | "verifyReleaseArtifact" | "resolveEligibleReleaseArtifact" | "resolveEligibleAppMetadata" | "resolvePublicSurfaceAuthority" | "resolvePublicSurfaceAuthorityVersion" | "createPublicSurface" | "transition";Names a public catalog command whose hostile input was rejected.
appRolesconstant
Section titled “appRoles”const appRoles: readonly [ "dashboard", "inbox", "files", "media", "sessions", "terminal",];Roles a user may assign to an App: the shell routes “open my inbox”, file
navigation, media and Session conversations to the App the Team chose.
dashboard marks an App that can open as a Team’s dashboard; the Team’s shell
selection, not a role choice, picks among them. Extend this list here; the Hub
role projection then requires the new role.
appCapabilityIdsconstant
Section titled “appCapabilityIds”const appCapabilityIds: readonly [ "agent.list", "agent.manage", "agent.read", "agent.send", "computer.list", "computer.readFile", "computer.writeFile", "computer.execute", "llm.generation", "media.generation", "games:servers", "apps.open", "app.storage", "team.workbenchHost", "marketplace.browse", "marketplace.purchase", "workflow.run", "world", "channels.read", "channels.personal.manage",];Host capabilities an App may request. A request is never authority; the Team’s installation grants decide. Extend this list here.
appHandlersconstant
Section titled “appHandlers”const appHandlers: readonly ["file.open"];Navigation requests an App can handle for the shell.
appStorageScopesconstant
Section titled “appStorageScopes”const appStorageScopes: readonly ["team", "member"];A declared layer of the App’s own JSON data; never a cross-Team scope.
emptyAppDeclarationconstant
Section titled “emptyAppDeclaration”const emptyAppDeclaration: AppDeclaration;The declaration of an App that asks for nothing.
parseAppIdconstant
Section titled “parseAppId”const parseAppId: (input) => AppId;Parse an opaque Global App identifier.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”parseAppTransitionIdconstant
Section titled “parseAppTransitionId”const parseAppTransitionId: (input) => AppTransitionId;Parse a Cairn-issued App transition identity.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”parseReleaseIdconstant
Section titled “parseReleaseId”const parseReleaseId: (input) => ReleaseId;Parse an opaque immutable Release identifier.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”parsePublicSurfaceIdconstant
Section titled “parsePublicSurfaceId”const parsePublicSurfaceId: (input) => PublicSurfaceId;Parse an opaque anonymous public-Surface identifier.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”parseArtifactRefconstant
Section titled “parseArtifactRef”const parseArtifactRef: (input) => ArtifactRef;Parse an opaque bounded artifact reference.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”parseIdempotencyKeyconstant
Section titled “parseIdempotencyKey”const parseIdempotencyKey: (input) => IdempotencyKey;Parse a caller-provided idempotency key.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”parseSourceRevisionconstant
Section titled “parseSourceRevision”const parseSourceRevision: (input) => SourceRevision;Parse a pinned lowercase Git source revision.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”parseSha256Digestconstant
Section titled “parseSha256Digest”const parseSha256Digest: (input) => Sha256Digest;Parse a lowercase SHA-256 digest.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”parseStableRouteconstant
Section titled “parseStableRoute”const parseStableRoute: (input) => StableRoute;Parse a canonical local origin-relative stable route.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
input |
unknown |
Returns
Section titled “Returns”isEmptyAppDeclaration()function
Section titled “isEmptyAppDeclaration()”function isEmptyAppDeclaration(declaration): boolean;An empty declaration is omitted from the manifest to keep digests stable.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
declaration |
AppDeclaration |
Returns
Section titled “Returns”boolean
issuePublicSurfaceId()function
Section titled “issuePublicSurfaceId()”function issuePublicSurfaceId(): PublicSurfaceId;Publisher issues customer Surface identities through Cairn, never from slugs.
Returns
Section titled “Returns”createAppReleaseCatalog()function
Section titled “createAppReleaseCatalog()”function createAppReleaseCatalog(options): AppReleaseCatalog;Create the App Release catalog.
The default Promise facade adapts each foreign port once before calling the same Effect-native core.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
options |
AppReleaseCatalogOptions |
Returns
Section titled “Returns”References
Section titled “References”AppBackendBinding
Section titled “AppBackendBinding”Re-exports AppBackendBinding