AssertAssignable was one-directional ([Actual] extends [Expected]), so a block declaring a field the contract doesn't accept passed silently (TypeScript's excess-property check only applies to fresh object literals, not conditional-type extends). Add a key-exactness check (Exclude<keyof Actual, keyof Expected> extends never) alongside the assignability check. Guard it with 'unknown extends Expected' so untyped (no defineEndpoint contract) routes still only warn, per the existing behaviour, instead of being forced to fail on every declared field. Add packages/cli/test/api-block-types.test.ts cases that regenerate a fixture and run the real TypeScript compiler (via bunx tsc) over the generated output, asserting on its diagnostics rather than on emitted text: matching fields compile clean; a wrong-typed field, an extra field (the Finding-A regression guard), and a missing required field all fail, each pointing at the offending block's __wrn_api_check_* line. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
basic-app
The reference app for WrNexus. Demonstrates every MVP feature.
app/
pages/index.wrn -> GET / (SSR + two counter components w/ props)
pages/about.wrn -> GET /about (pure SSR, zero JS)
pages/reactive.wrn -> GET /reactive (reactive directives, no component)
pages/hello.wrn -> GET /hello (.wrn language, compiled reactive page)
api/hello.ts -> GET /api/hello
api/echo.ts -> GET|POST /api/echo
middleware/auth.ts -> runs first (alphabetical)
middleware/logger.ts -> runs second
realtime/chat.ts -> ws /realtime/chat
components/counter.wrn -> server-rendered component: data-component="counter"
styles/global.css -> global stylesheet -> /__wrnexus/styles.css (every page)
public/
favicon.ico -> framework default if this file is absent
robots.txt -> GET /robots.txt
site.webmanifest -> GET /site.webmanifest
wrnexus.config.ts -> global SEO + head injection + CSS processor + security/CORS config
wrnexus.config.ts shows global SEO defaults, how to use a CSS framework via CDN
(head), or a real Tailwind/PostCSS build (styles.process). It also enables
example CORS origins and documents the default security headers. To use an npm
framework, @import it in app/styles/global.css.
app/pages/hello.wrn demonstrates a page-level .wrn seo block plus direct
.wrn access to cookies, session, and the CSR localStorage snapshot.
Run from the repo root:
bun install
bun run dev # serves this app at http://localhost:3000