directory.ts previously exported a plain (ctx: Context) => ... handler.
With that shape ApiInput<> resolved to unknown, so the generated
__wrn_api_check assertion for the demo page passed trivially even with
a field the endpoint does not accept -- the worked example did not
demonstrate the type safety it exists to demonstrate.
Rewrite directory.ts to use defineEndpoint with a schema (matching
typed-user.ts), which gives the generated assertion a real input type
to check against. Confirmed: adding an unaccepted field to the block's
request body now fails typecheck naming
__wrn_api_check_searchDirectory; removing it passes with zero net
diff.
Fix a real bug this surfaced: packages/core/src/endpoint.ts only read
its input from a second 'rawInput' argument, but the actual HTTP
router (packages/dev-server/src/runtime.ts handleApi) invokes route
handlers as handler(ctx) with no second argument. Every
defineEndpoint-based route -- including the pre-existing typed-user.ts
example -- silently received an empty/undefined input through the
real router (confirmed via curl: valid typed-user payloads were
rejected as 'Required'; directory's name filter matched every record
regardless of query). Fixed by having the endpoint wrapper parse the
request itself (query params for GET/HEAD, JSON body otherwise) when
no rawInput is explicitly supplied, while still honoring an explicit
rawInput for direct/unit-test callers.
Also update api-block-demo.wrn's response section: defineEndpoint
wraps handler output as { data: ... }, so the block's raw response
body is now { data: { users: [...] } } -- response reads
data.data.users instead of data.users.
Re-verified in a real browser after the endpoint rewrite and the
router fix: search returns exactly "Ajay, Asha", exactly one
POST /api/directory carrying x-csrf-token, and the error section
still runs cleanly (no exception, empty result) on a missing route.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
WRNexusJS
WRNexusJS is a compiler-driven, SSR-first, Bun-native full-stack framework for building secure, fast, maintainable applications with .wrn pages, layouts, components, stores, server functions, client functions, typed outputs, APIs, validation, authentication, realtime rooms, and production tooling.
Current framework version: 0.8.0
Core principles
- Secure by default with CSP, CSRF, safe serialization, URL policies, request limits, SSRF protection, secret scanning, and release gates.
- Performance-first SSR with zero framework JavaScript for static pages and selective hydration for interactive pages.
- One compiler-understood
.wrnmodel for markup, props, state, outputs, and runtime-specific functions. - Backward-compatible package upgrades with migrations, generated references, validation scripts, and private publishing controls.
- Package kits that give developers public helpers, package tests, documentation, and complete UI blocks where a package has a developer-facing interface.
Quick start
bun install
bun run validate:0.8
bun run check
bun run dev
Create or upgrade a project:
bunx @wrnexus/cli@0.8.0 create my-app
bunx @wrnexus/cli@0.8.0 update --version=0.8.0 --report
Package kits in 0.8
All 39 framework packages expose a documented helper/API surface and package tests. UI-facing packages additionally own complete .wrn blocks composed from @wrnexus/ui:
@wrnexus/auth— complete account, sign-in, sign-up, MFA, passkey, recovery, device, provider, and security blocks.@wrnexus/captcha— challenge, field, status, extraction, verification, response, and context helpers.@wrnexus/i18n— recursive locale loading, fallback chains, request resolution, SSR/browser translations, language controls, and formatters.@wrnexus/image— responsive picture plans, secure loaders, placeholders, preload hints, audits, and image blocks.@wrnexus/realtime— typed messages, room connections, presence, typing, metadata, composer, status, and message blocks.@wrnexus/uploader— upload attributes, result validation, formatting, dropzone, and status blocks.@wrnexus/validation— parse/throw helpers, consistent error responses, summaries, and field errors.@wrnexus/ui— the complete shared design-system component catalog.
Infrastructure packages remain helper/API-only so database, encryption, security, compiler, server, and build packages do not pull browser UI into production server code.
Security note for encrypted HTTP bodies
@wrnexus/encryption supports authenticated application-layer request and response envelopes with method, path, request-ID, timestamp, expiry, key-rotation, body-size, and replay binding.
This feature does not replace HTTPS. It is appropriate for service-to-service calls, native/mobile clients, controlled agents, or selected fields with server-managed keys. It cannot hide data from an end user when a browser receives the decryption key.
Validation commands
bun run audit:packages
bun run test:package-kits
bun run validate:0.8
bun run security:framework
bun run sbom
bun run benchmark:framework
bun run validate:staging
bun run check