Search by

kumwe / producer

llewellyn

The PHP producer for Kumwe Studio: receives canonical Studio compositions and makes them real - validated wire handling, semantic server-side rendering, and design-token CSS - while your application keeps all authority and storage.

Package info

github.com/kumwe/producer

pkg:composer/kumwe/producer

Statistics

Installs: 1 530

Dependents: 2

Suggesters: 0

Stars: 0

Open Issues: 0

v0.3.0 2026-09-09 13:50 UTC

This package is auto-updated.

Last update: 2026-09-12 15:16:03 UTC


README

Packagist version Build PHP License

Studio designs it. Producer makes it real. Your application owns it.

Producer is the PHP realization layer for Kumwe Studio, the schema-aware visual composition platform. Studio hands your application a canonical, portable JSON composition — never markup, never styles, never code. Producer is what turns that composition into reality on a PHP host:

  • Wire handling — parses and validates Studio's request envelopes, routes the closed operation set, and answers with strict canonical JSON and the stable twelve-category error taxonomy.
  • Rendering — turns a published composition into semantic, fully escaped HTML with working no-JavaScript fallbacks for the complete Studio block catalog.
  • Stylesheets — generates the static CSS a design's tokens and layout vocabulary imply; nothing is computed per request and nothing is inlined.
  • Contract proof — vendors Studio 0.1.0-beta.3 at source commit 42b149251a9f17a2ef8f32db0d9dd1ac2fcfec8a, digest-verifies all 55 protocol schemas and all 301 testkit corpus members, and replays the published conformance vectors, so what this library claims is what it proves.

Producer deliberately contains no authority, no storage, no Node.js, and no render-time code generation — your application keeps authentication, authorization, persistence, and templates, and implements Producer's small port interfaces with its own services. The full rules live in the charter; the division of labour with Studio and with host applications is recorded in the host agreement.

The pipeline

Stage Owner What happens
Design Studio (browser) An author composes typed, theme-bounded blocks; Studio emits canonical JSON
Wire Producer Envelope validated, operation routed, host answers through its own ports
Authority and storage Your application Authorization, revisions, audit, persistence — all yours
Realization Producer Published composition → semantic HTML + generated stylesheet
Delivery Your application Embeds the render result in its own templates and serves Studio's prebuilt assets

How it is built

The library is layered with one dependency direction — Canonical JSON, the schema-property profile, the error taxonomy, the wire layer, rendering, stylesheets — each proven by replaying the vendored Studio conformance corpora before the next layer consumes it. The engineering standard states the architecture, code, testing, and documentation rules in full: strict types, final classes, injected authority, centralized escaping, deterministic output, typed refusals with stable codes, and a suite that proves intended outcomes only — the conformance corpora are the spine, negative paths are first-class, and frivolous tests are forbidden.

Producer is also written to be ported. The contract is language-neutral JSON, so a Python or TypeScript sibling implements the same corpora and claims conformance the same way; the porting guide gives an implementer the order, the boundaries, and the subtleties, so a port needs this repository and nothing else.

Exact document admission

Hosts and extension tooling can validate decoded Studio documents through the one sealed, release-pinned authority. The registry accepts the thirteen published runtime document kinds, validates the seven contextual authoring, session-configuration, deployment and host-capabilities documents through their pinned root or named definitions, and loads only Producer's digest-verified Composer resources; callers cannot inject schemas, roots, references, patterns, directories, or alternate schema paths.

use Kumwe\Producer\Schema\StudioDocumentSchemaRegistry;

$validation = StudioDocumentSchemaRegistry::fromVendoredCorpus()
    ->validate('blueprint', $decodedDocument);

if (!$validation->valid()) {
    foreach ($validation->diagnostics() as $diagnostic) {
        // $diagnostic->instancePath, ->keyword, ->message
    }
}

StudioContractResources::releaseRecord() exposes immutable typed release coordinates and release readiness. Its browser-artifact surface binds the manifest, browser module, and enhancement runtime to exact package paths, byte counts, SHA-256 content hashes, and SRI values. The Composer package also carries the manifest's complete fourteen-file redistribution notice/license closure, with every member package-path and digest bound by the same proof. Its private import gate additionally proves the deterministic 74-member outer ustar archive, detached checksum, and byte equality with the npm browser distribution. The 1.4 MB archive and checksum are provenance inputs, not Composer payload. testkitBytes() reads only digest-verified corpus-manifest members for consumer conformance tests. None of these APIs exposes the package root or a generalized filesystem reader. Decoded inputs must use the canonical JSON shape (stdClass objects and list arrays) and the interoperable ECMAScript safe-integer range.

Status

Producer is aligned to the provenance-backed eight-package Studio 0.1.0-beta.3 npm publication at commit 42b149251a9f17a2ef8f32db0d9dd1ac2fcfec8a. It vendors 55 schemas and 301 corpus files, reproduces the released thirty-one-operation wire across ten operational ports (including the seven authoring operations), and claims zero Studio conformance profiles. Canonical JSON, exact document-schema admission, host-atomic mutation and protected replay, rendering, rich text, and stylesheets are corpus-proven. The Studio asset manifest also proves the exact browser module and enhancement runtime bytes carried by the npm packages and all fourteen redistribution notice/license members that accompany those bytes.

The governed Studio prerelease publishes the exact deterministic 74-member outer browser archive and its detached checksum, and the PIN was regenerated from those public downloads, binding their live URLs, bytes, and digests as one fail-closed contract proof. The Kumwe\Producer\Deployment layer additionally locates the pinned browser module and enhancement runtime wherever a host serves them (its own origin, a mirror, or a public npm CDN such as https://cdn.jsdelivr.net/npm) with the manifest SRI value, emits the inert per-mount deployment pair after pinned-schema and release-binding proof, publishes the two manifest Content-Security-Policy values widened only by exact origins, and admits the same-origin fetch tuple before a request body is read. The optional Twig bridge remains roadmap work and is not claimed. See the roadmap for the precise boundary.

Installation

composer require kumwe/producer:0.3.0

PHP 8.1 or newer with ext-json and ext-mbstring. No runtime Composer dependencies. Hosts pin Producer exactly while Studio's contract is a prerelease; qualify a new version against their integration tests before changing that pin. See published versions for updates.

Core integration and support

Core supplies the host ports described in the host guide and retains authorization, persistence, revisions, lifecycle and delivery. The release record binds the API and Studio resources to the consumer contract.

Use GitHub issues for reproducible bugs and feature requests. See the public API, release history and license.

Development

From a repository checkout (development tooling is intentionally absent from package archives):

composer validate --strict
composer install --no-interaction
php tools/check.php   # lint, API/architecture gates, contract proof, suite