B1: qualify each generated __wrn_api_check_* assertion name with a short hash of the page's path (relative to app/, for reproducibility across checkouts) so two pages declaring a same-named block no longer collide with an identical type alias (TS2300). B2: skip assertion emission for any block that is not client-mode, or that has zero declared request fields. ssr sectioned blocks can never declare a request and always fell back to Record<string, never>, whose keyof is `string` -- making the key-exactness arm of AssertAssignable evaluate to false unconditionally (TS2344) on every ssr sectioned block regardless of correctness. Chose to skip both non-client blocks and zero-field client blocks, since neither has anything meaningful to assert type-safety about. B3: only resolve the endpoint's input (query params / ctx.req.json()) when the endpoint declares an input schema. Previously the router-set fix accidentally read the request body unconditionally, so a handler with no input schema that parses the request itself hit ERR_BODY_ALREADY_USED. B4: run response/error bodies in client-mode api blocks through eraseFunctionTypes, matching every other browser-bound body in client-codegen.ts, so a TypeScript-only construct inside one (e.g. an annotated locally-declared function) doesn't reach the .mjs artifact. B5: only exclude "api" from state/prop destructuring in the generated browser module when the page actually has client-mode api blocks (i.e. there is a real `api` binding to shadow). Previously "api" was always excluded, so a page with `state api` and no api blocks got an undeclared `api` reference (ReferenceError) in client code. B6: prefix each emitted assertion with `export`, so it isn't flagged as an unused local under a downstream project's noUnusedLocals (TS6196). B7: wrnexusCallApi now resolves with undefined for an ok 204/205 response, or an ok response with an empty/unparseable body, instead of rejecting with "Response was not valid JSON" -- matching the spec's failure table (error path only for non-2xx, network failure, or an actually unparseable body on a non-empty response). Regenerated examples/basic-app's generated types and editor bundles to match. Confirmed the example's type gate still fails when an unaccepted field is added to a request body, and passes cleanly otherwise. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
WRNexusJS
WRNexusJS is a compiler-driven, SSR-first, Bun-native full-stack framework for building secure, fast, maintainable applications with .wrn pages, layouts, components, stores, server functions, client functions, typed outputs, APIs, validation, authentication, realtime rooms, and production tooling.
Current framework version: 0.8.0
Core principles
- Secure by default with CSP, CSRF, safe serialization, URL policies, request limits, SSRF protection, secret scanning, and release gates.
- Performance-first SSR with zero framework JavaScript for static pages and selective hydration for interactive pages.
- One compiler-understood
.wrnmodel for markup, props, state, outputs, and runtime-specific functions. - Backward-compatible package upgrades with migrations, generated references, validation scripts, and private publishing controls.
- Package kits that give developers public helpers, package tests, documentation, and complete UI blocks where a package has a developer-facing interface.
Quick start
bun install
bun run validate:0.8
bun run check
bun run dev
Create or upgrade a project:
bunx @wrnexus/cli@0.8.0 create my-app
bunx @wrnexus/cli@0.8.0 update --version=0.8.0 --report
Package kits in 0.8
All 39 framework packages expose a documented helper/API surface and package tests. UI-facing packages additionally own complete .wrn blocks composed from @wrnexus/ui:
@wrnexus/auth— complete account, sign-in, sign-up, MFA, passkey, recovery, device, provider, and security blocks.@wrnexus/captcha— challenge, field, status, extraction, verification, response, and context helpers.@wrnexus/i18n— recursive locale loading, fallback chains, request resolution, SSR/browser translations, language controls, and formatters.@wrnexus/image— responsive picture plans, secure loaders, placeholders, preload hints, audits, and image blocks.@wrnexus/realtime— typed messages, room connections, presence, typing, metadata, composer, status, and message blocks.@wrnexus/uploader— upload attributes, result validation, formatting, dropzone, and status blocks.@wrnexus/validation— parse/throw helpers, consistent error responses, summaries, and field errors.@wrnexus/ui— the complete shared design-system component catalog.
Infrastructure packages remain helper/API-only so database, encryption, security, compiler, server, and build packages do not pull browser UI into production server code.
Security note for encrypted HTTP bodies
@wrnexus/encryption supports authenticated application-layer request and response envelopes with method, path, request-ID, timestamp, expiry, key-rotation, body-size, and replay binding.
This feature does not replace HTTPS. It is appropriate for service-to-service calls, native/mobile clients, controlled agents, or selected fields with server-managed keys. It cannot hide data from an end user when a browser receives the decryption key.
Validation commands
bun run audit:packages
bun run test:package-kits
bun run validate:0.8
bun run security:framework
bun run sbom
bun run benchmark:framework
bun run validate:staging
bun run check