Web Bro publishing pipeline
The exact publication order used by both the main publisher and the upgraded Code Editor publisher.
currentstatus
App developers ยท Security developersaudience
School-GIT docssource
SCHX nativeruntime
SCHX / FEATURE LAYER
System flow
1
Upload media
2
Create/refresh owner draft
3
Media integrity scan
4
Code security scan
5
Immutable version commit
SCHX / FEATURE LAYER
Source map
- app/cdn/web-bro/publish/page.tsx
- app/api/cdn/apps/media/security/scan/route.ts
- app/api/cdn/apps/security/scan/route.ts
- app/api/cdn/apps/[appId]/versions/route.ts
SCHX / FEATURE LAYER
Architecture diagram
mermaidflowchart TD
A[Package + metadata + media] --> B[Owner-only draft]
B --> C[Media integrity scan]
C -->|block| D[Remain draft]
C -->|pass + mediaScanId| E[Code security scan]
E -->|block| D
E -->|pass + securityScanId| F[Immutable version commit]
F --> G[Installable Web Bro release]SCHX / FEATURE LAYER
Media is the first security gate
The exact uploaded logo, screenshots and feature videos are analyzed before code security. A blocked media report prevents code scanning and immutable publication.
SCHX / FEATURE LAYER
Code scan is bound to the media scan
The code security request receives the mediaScanId. The immutable version commit then receives both the mediaScanId and securityScanId so the authoritative server can reject stale or mismatched scan context.
SCHX / FEATURE LAYER
Failed updates do not replace published versions
A failed new version remains a private/draft attempt. Previously published immutable versions remain intact.
SCHX / FEATURE LAYER