kcode-k1-web-package 0.1.2

Validate authority-namespaced buildless K1 Web package source
Documentation
# K1 Web package

`kcode-k1-web-package` defines and validates authority-namespaced, immutable K1 Web package source.

## Public values

```rust
pub struct AuthorityId;
pub struct WebFamily;
pub struct WebId;
pub struct DependencySelector;
pub struct SourceFile;
pub struct WebDependency;
pub struct SourcePackage;
pub struct PackageError;

pub fn validate_source_path(path: &str) -> Result<(), PackageError>;
pub fn project_manifest_version(
    files: &[SourceFile],
    version: &Version,
) -> Result<Vec<SourceFile>, PackageError>;
```

Logical names use lowercase kebab case. Package versions are stable SemVer without prerelease or build metadata. Dependency selectors are `*` or one to three canonically spelled decimal components.

`SourcePackage::new` validates a complete immutable public package. Source paths use safe slash-relative spelling, are unique, and may not collide with a file ancestor. The package requires UTF-8 `Documentation.md`, a strict UTF-8 `k1-web.json`, and UTF-8 JavaScript entry and test files named by that manifest. Manifest identity must match the supplied `WebId` canonically. Dependencies are parsed, validated, sorted, and deduplicated. Other files may contain arbitrary bytes. Retained files are path-sorted.

`validate_source_path` exposes the exact safe slash-relative source-path policy used by `SourcePackage`: paths are nonempty and bounded, contain ordinary nonempty components, and reject absolute paths, `.`, `..`, backslashes, colons, NUL bytes, and empty components.

`project_manifest_version` requires a stable target version and exactly one UTF-8, structurally valid, strict `k1-web.json` whose existing version is canonical stable SemVer. It clones and path-sorts the complete supplied tree, changing only the top-level manifest `version` JSON string token. Every other byte is preserved, including manifest whitespace and key order, text files, and binary siblings.

This crate performs no filesystem or network I/O, authorization, dependency selection, persistence, checking, publication, installation, or deployment.