ClintchizandClaude Opus 5 a20f143acb fix: isolate test globals, close tags at every caret, trim the runtime
Three pre-existing issues that the previous commit worked around rather
than solved.

Test global pollution. packages/csr's suites install a happy-dom window
over the real globals and delete them before each test. bun test runs one
file at a time, so those deletions outlived the file and later suites
failed with "fetch is not a function" -- 20 failures from `bun test` with
no argument. They now restore what they captured. The editor's Node tests
shim the vscode host by patching Module._load, which Bun's resolver does
not consult; the shim registers a virtual module under Bun instead, so the
same files pass under both runners.

Multi-cursor tag auto-close. The handler now closes the tag at every
caret. Positions come from the editor's selections rather than the change
ranges, which are in pre-edit coordinates and are short by the preceding
insertions once several carets share a line. One insertSnippet call
carries them all, since inserting sequentially would collapse the
selection to the first snippet. Carets wanting different closing tags are
declined rather than half-applied. Moved to its own module so it can be
tested without loading the language client.

Runtime size. Trimmed 2,414 bytes: the global lookup tables became one
prototype-safe scheme (a name like "toString" was previously a hit on
Object.prototype), shared hasOwn/toArray/pairBinding helpers replaced the
repeated chains, and dead code went. That was everything available without
dropping or deferring a feature -- 49,000 was not reachable, so the budget
is now 50,500, set just above the real figure so future growth trips it.

Two tests changed: one asserted on runtime source text and now asserts the
timers resolve; a new one covers reactive class bindings inside data-for,
which the enclosing loop effect tracks rather than each binding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 10:14:18 +05:30
2026-08-01 01:09:58 +05:30
2026-07-12 15:55:18 +05:30
2026-07-12 15:55:18 +05:30
2026-08-11 13:40:03 +05:30
2026-08-02 23:18:51 +05:30
2026-08-02 23:18:51 +05:30
2026-08-02 23:18:51 +05:30
2026-08-02 23:18:51 +05:30
2026-08-02 23:18:51 +05:30

WRNexusJS

WRNexusJS is a compiler-driven, SSR-first, Bun-native full-stack framework for building secure, fast, maintainable applications with .wrn pages, layouts, components, stores, server functions, client functions, typed outputs, APIs, validation, authentication, realtime rooms, and production tooling.

Current framework version: 0.8.0

Core principles

  • Secure by default with CSP, CSRF, safe serialization, URL policies, request limits, SSRF protection, secret scanning, and release gates.
  • Performance-first SSR with zero framework JavaScript for static pages and selective hydration for interactive pages.
  • One compiler-understood .wrn model for markup, props, state, outputs, and runtime-specific functions.
  • Backward-compatible package upgrades with migrations, generated references, validation scripts, and private publishing controls.
  • Package kits that give developers public helpers, package tests, documentation, and complete UI blocks where a package has a developer-facing interface.

Quick start

bun install
bun run validate:0.8
bun run check
bun run dev

Create or upgrade a project:

bunx @wrnexus/cli@0.8.0 create my-app
bunx @wrnexus/cli@0.8.0 update --version=0.8.0 --report

Package kits in 0.8

All 39 framework packages expose a documented helper/API surface and package tests. UI-facing packages additionally own complete .wrn blocks composed from @wrnexus/ui:

  • @wrnexus/auth — complete account, sign-in, sign-up, MFA, passkey, recovery, device, provider, and security blocks.
  • @wrnexus/captcha — challenge, field, status, extraction, verification, response, and context helpers.
  • @wrnexus/i18n — recursive locale loading, fallback chains, request resolution, SSR/browser translations, language controls, and formatters.
  • @wrnexus/image — responsive picture plans, secure loaders, placeholders, preload hints, audits, and image blocks.
  • @wrnexus/realtime — typed messages, room connections, presence, typing, metadata, composer, status, and message blocks.
  • @wrnexus/uploader — upload attributes, result validation, formatting, dropzone, and status blocks.
  • @wrnexus/validation — parse/throw helpers, consistent error responses, summaries, and field errors.
  • @wrnexus/ui — the complete shared design-system component catalog.

Infrastructure packages remain helper/API-only so database, encryption, security, compiler, server, and build packages do not pull browser UI into production server code.

Security note for encrypted HTTP bodies

@wrnexus/encryption supports authenticated application-layer request and response envelopes with method, path, request-ID, timestamp, expiry, key-rotation, body-size, and replay binding.

This feature does not replace HTTPS. It is appropriate for service-to-service calls, native/mobile clients, controlled agents, or selected fields with server-managed keys. It cannot hide data from an end user when a browser receives the decryption key.

Validation commands

bun run audit:packages
bun run test:package-kits
bun run validate:0.8
bun run security:framework
bun run sbom
bun run benchmark:framework
bun run validate:staging
bun run check
S
Description
No description provided
Readme MIT
45 MiB
Languages
JavaScript 71.7%
TypeScript 28.2%