C++ SCHX ยท rev 4
Web Bro ยท current

Web Bro publishing pipeline

The exact publication order used by both the main publisher and the upgraded Code Editor publisher.

currentstatus
App developers ยท Security developersaudience
School-GIT docssource
SCHX nativeruntime
SCHX / FEATURE LAYER

System flow

1

Upload media

2

Create/refresh owner draft

3

Media integrity scan

4

Code security scan

5

Immutable version commit

SCHX / FEATURE LAYER

Source map

  • app/cdn/web-bro/publish/page.tsx
  • app/api/cdn/apps/media/security/scan/route.ts
  • app/api/cdn/apps/security/scan/route.ts
  • app/api/cdn/apps/[appId]/versions/route.ts
SCHX / FEATURE LAYER

Architecture diagram

mermaidflowchart TD
A[Package + metadata + media] --> B[Owner-only draft]
B --> C[Media integrity scan]
C -->|block| D[Remain draft]
C -->|pass + mediaScanId| E[Code security scan]
E -->|block| D
E -->|pass + securityScanId| F[Immutable version commit]
F --> G[Installable Web Bro release]
SCHX / FEATURE LAYER

Media is the first security gate

The exact uploaded logo, screenshots and feature videos are analyzed before code security. A blocked media report prevents code scanning and immutable publication.

SCHX / FEATURE LAYER

Code scan is bound to the media scan

The code security request receives the mediaScanId. The immutable version commit then receives both the mediaScanId and securityScanId so the authoritative server can reject stale or mismatched scan context.

SCHX / FEATURE LAYER

Failed updates do not replace published versions

A failed new version remains a private/draft attempt. Previously published immutable versions remain intact.

SCHX / FEATURE LAYER

Related documentation