C++ SCHX ยท rev 4
CDN Editor ยท current

Editor publication security

The Code Editor publisher now uses the same real media-integrity and code-security pipeline as the main Web Bro publisher.

currentstatus
Editor developers ยท Security developersaudience
School-GIT docssource
SCHX nativeruntime
SCHX / FEATURE LAYER

System flow

1

Editor project snapshot

2

Media scan

3

mediaScanId

4

Code scan

5

securityScanId

6

Immutable commit

SCHX / FEATURE LAYER

Source map

  • components/cdn/apps/code-editor/EditorStateManager.ts
  • components/cdn/apps/code-editor/EditorAppPublishPanel.tsx
  • components/cdn/apps/code-editor/EditorWindow.tsx
SCHX / FEATURE LAYER

No separate โ€œeditor scannerโ€ shortcut

The editor publication flow calls the same Web Bro media-security and code-security APIs used by the standalone publisher. It renders the current AppMediaIntegrityReport and AppSecurityScanReport components.

SCHX / FEATURE LAYER

Gate order is enforced

A blocked media scan stops the pipeline before code scanning. A blocked code scan stops the pipeline before the immutable version endpoint. Successful scan identifiers are forwarded into the authoritative commit request.

SCHX / FEATURE LAYER

Runtime classification fixes

Runtime entries such as root-level app.js are allowed to remain runtime files. Source folders such as src/, source/, tests and configuration files remain source-oriented. Path traversal is rejected before package construction.

SCHX / FEATURE LAYER

Related documentation