Editor publication security
The Code Editor publisher now uses the same real media-integrity and code-security pipeline as the main Web Bro publisher.
System flow
Editor project snapshot
Media scan
mediaScanId
Code scan
securityScanId
Immutable commit
Source map
- components/cdn/apps/code-editor/EditorStateManager.ts
- components/cdn/apps/code-editor/EditorAppPublishPanel.tsx
- components/cdn/apps/code-editor/EditorWindow.tsx
No separate โeditor scannerโ shortcut
The editor publication flow calls the same Web Bro media-security and code-security APIs used by the standalone publisher. It renders the current AppMediaIntegrityReport and AppSecurityScanReport components.
Gate order is enforced
A blocked media scan stops the pipeline before code scanning. A blocked code scan stops the pipeline before the immutable version endpoint. Successful scan identifiers are forwarded into the authoritative commit request.
Runtime classification fixes
Runtime entries such as root-level app.js are allowed to remain runtime files. Source folders such as src/, source/, tests and configuration files remain source-oriented. Path traversal is rejected before package construction.