Explanation
From Page Spec to standalone artifact
One constrained input, one deterministic output, no runtime framework.
A Page Spec describes meaning. The compiler decides structure, styling, and behavior.
Minimal specyaml
version: 1
meta:
title: Example
theme:
preset: editorial
policy:
network: deny
blocks:
- type: text
text: HelloPipeline stages
JSON or YAML becomes a plain object at the input boundary.
Schema, bounds, and policy checks report stable diagnostics.
Nested authoring input becomes a flat node graph with stable IDs.
Registry resolution, theme resolution, and block rendering.
Only used assets and runtime features are emitted.
Determinism is observable
Identical normalized input and options produce byte-identical output.
Trust boundary
Trust boundary
- Untrusted Page Spec
specthen to compilervalidated input - Compiler
compilerthen to artifactescaped output - Trusted Artifact
artifact
Rendered as a structured fallback because no diagram adapter is configured.
Escaping happens at emission, not at parse time, so a value that is safe in one context is not assumed safe in another. URLs are allowlisted per action and per widget, and embedded JSON is serialized for a script context.
Guarantees
- Network
- Denied unless the spec opts in
- Scripts
- Compiler-owned only
- Fonts
- No remote fetches
- Focus
- Visible and keyboard-reachable