{"_id":"@bytesell/slurp-compiler-wasm","name":"@bytesell/slurp-compiler-wasm","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@bytesell/slurp-compiler-wasm","version":"0.1.0","description":"WebAssembly build of the Slurp compiler: parse, render, validate, extract_schema and render_section for browser and editor hosts.","license":"MIT","author":"ByteSell LLC","repository":{"type":"git","url":"git+https://github.com/bytesell/slurp.git","directory":"compiler-wasm"},"homepage":"https://github.com/bytesell/slurp#readme","main":"./index.cjs","types":"./index.d.ts","bugs":{"url":"https://github.com/bytesell/slurp/issues"},"devDependencies":{"typescript":"^5.9.3"},"publishConfig":{"access":"public"},"scripts":{"build":"node build.mjs","typecheck":"tsc --noEmit -p tsconfig.json"},"_nodeVersion":"26.0.0","_id":"@bytesell/slurp-compiler-wasm@0.1.0","dist":{"integrity":"sha512-VsrKFk6AEadrm7kMrrk46PE4Sy8l/apwgm/2sM9IuP+PuPRElo8tZiByl17uygFqcpdpP7RCYI6YKAlhFd4Tow==","shasum":"70d34452ad465c8a532b940141bfecd606138a7b","tarball":"https://registry.npmjs.org/@bytesell/slurp-compiler-wasm/-/slurp-compiler-wasm-0.1.0.tgz","fileCount":8,"unpackedSize":1750497,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC4SFbome50PNLlPT4oKmUez7pItmdcu/q3a7M0WLHhxQIgZhIE++68rFwwDHbIcYUYMmBNBbLV7EWg+VGCvySqPoA="}]},"_npmUser":{"name":"ldstr","email":"dip96950@gmail.com"},"directories":{},"maintainers":[{"name":"ldstr","email":"dip96950@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/slurp-compiler-wasm_0.1.0_1785936914692_0.5667073864612893"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-05T13:35:14.530Z","0.1.0":"2026-08-05T13:35:14.844Z","modified":"2026-08-05T13:35:15.101Z"},"maintainers":[{"name":"ldstr","email":"dip96950@gmail.com"}],"description":"WebAssembly build of the Slurp compiler: parse, render, validate, extract_schema and render_section for browser and editor hosts.","homepage":"https://github.com/bytesell/slurp#readme","repository":{"type":"git","url":"git+https://github.com/bytesell/slurp.git","directory":"compiler-wasm"},"author":"ByteSell LLC","bugs":{"url":"https://github.com/bytesell/slurp/issues"},"license":"MIT","readme":"# @bytesell/slurp-compiler-wasm\n\nThe WebAssembly build of the Slurp compiler. It exposes the seven entry points in\n`compiler/src/wasm/mod.rs` to JavaScript hosts: an editor, a preview pane, a\nlanguage server, or a browser.\n\n## Build\n\nFrom a fresh clone, from the repository root:\n\n```bash\npnpm install\npnpm --filter @bytesell/slurp-compiler-wasm build\n```\n\n`pnpm build` at the root also builds it, ahead of the packages that consume it.\n\nThe build needs [`wasm-pack`](https://rustwasm.github.io/wasm-pack/installer/)\non `PATH` (`cargo install wasm-pack --locked`). The `wasm32-unknown-unknown`\nrustup target is installed automatically if it is missing. Output lands in\n`pkg/`, which is a build artifact and is not committed.\n\nTo build for a browser bundler instead of Node:\n\n```bash\nnode build.mjs --target web\n```\n\n## Everything returns a JSON string\n\n`JsValue::from_str` is how each export serialises, so **every function returns a\n`string` that you must `JSON.parse`**. It does not return an object.\n\nThe TypeScript declarations encode this: an export returns `JsonString<T>`, a\nbranded `string` that will not typecheck as a `T`. Cross the boundary with the\nexported `parseJson` helper.\n\n```ts\nimport { parse, parseJson } from '@bytesell/slurp-compiler-wasm'\n\nconst result = parseJson(parse('<h1>${title}</h1>'))\n//    ^ ParseResult\nif (!result.ok) console.error(result.errors)\n```\n\nThe parsed shapes (`ParseResult`, `RenderResult`, `SchemaResult`, `SlurpError`)\ncome from `shared/interfaces.ts`, so there is one definition of each rather than\na copy per consumer.\n\n## Exports\n\n| Export | Returns | Notes |\n|---|---|---|\n| `parse(source)` | `ParseResult` | `ast` is `null` only when lexing failed outright |\n| `render(astJson, contextJson)` | `RenderResult` | production mode |\n| `render_dev(astJson, contextJson)` | `RenderResult` | development mode; see below |\n| `validate(source)` | `SlurpError[]` | parse diagnostics only, a flat array of errors and warnings |\n| `validate_full(source, isMiddleware)` | `SlurpError[]` | `validate` **plus the compile-time security walk**; see below |\n| `extract_schema(source)` | `SchemaResult` | `schema` is `null` when none is declared, which is not an error |\n| `render_section(astJson, stateJson, contextJson)` | `RenderResult` | merges saved editor state over schema defaults |\n\n### `render` vs `render_dev`\n\nTwo of the renderer's advisories are recorded only in development mode:\nCSS-structural characters stripped from a `style` value, and an un-annotated\ninterpolation in a JavaScript-evaluated attribute. In production both happen\nsilently. `{debug expr}` also renders only in development.\n\nThat is the right trade for a server-side hot path and the wrong one for an\neditor, where a `style` value quietly losing characters is what a preview should\nsurface. Editors and preview panes should call `render_dev`. `render` is\nunchanged, so existing hosts keep production behaviour.\n\nThe budget diagnostics are **not** among them. Loop truncation at 1,000 items,\nthe output-byte budget and the render-depth budget are reported in both modes,\nbecause each one silently removes content from the page.\n\n### `validate` vs `validate_full`\n\n**Prefer `validate_full` if you are building an authoring tool, a publish gate or\na CI check.** These two do not report the same thing, and the difference is\nsecurity-relevant.\n\n`validate` parses. `validate_full` parses **and** runs the compiler's\ncompile-time security walk (`slurp_compiler::check_security`), which is where\nseveral rules live that the parser knows nothing about:\n\n- an unfiltered `${ }` in a `<script>` body,\n- a `| js` slot in JavaScript statement position, where escaping the quote\n  characters cannot contain a value,\n- `env.SLURP_SECRET_*`, in any file,\n- `request.*` outside middleware,\n- `{redirect}` and `{next}` outside middleware.\n\nA tool that calls only `validate` therefore tells an author their file is clean\nand then `slurp build` rejects it. The two stay separate rather than merged so\npure editor-preview hosts are unaffected.\n\nAt the call site:\n\n- **`isMiddleware` must match the value the eventual compile will use.** The\n  rules differ: `request.*` and `{redirect}` are legal only in\n  middleware, and most other path roots are illegal there. A caller with no way\n  to know passes `false`, which is what `compile`, `compile_with_registry` and\n  the `slurp validate` CLI all do.\n- **The security walk returns on its first violation** (it is a `Result`, not an\n  accumulator), so at most one security diagnostic is appended per call, while\n  parse diagnostics accumulate. Fix the reported one and re-run to see the next.\n\n## Security\n\n**`parse`, `render`, `render_dev`, `validate`, `extract_schema` and\n`render_section` do not run `security_check`; `validate_full` does.**\n`SLURP_SECRET_*` access, middleware scope and redirect restrictions are\nserver-side concerns enforced by the host, and a template that violates them\nparses cleanly through the first six. A preview is not a deploy.\n\nA WASM **render** enforces none of those rules either. It does still apply the\nrenderer's own script-context backstops, so an undeclared `${ }` in a `<script>`\nbody and a false `| js` claim are caught there, but do not use a WASM render as a\nproduction render path.\n\nSee the note at the top of `compiler/src/wasm/mod.rs` and\n[the security model](https://github.com/bytesell/slurp/blob/main/docs/security-model.md).\n","readmeFilename":"","_rev":"1-54a36de7267a770da6916331f003d302"}