Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,9 @@ jobs:
- name: Install pinned OCR build inputs
run: npm ci --ignore-scripts

- name: Type-check migrated browser modules
run: npm run typecheck

- name: Verify prepared production OCR assets
run: npm run build

Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,2 +1,3 @@
node_modules/
dist/
.ts-build/
1 change: 1 addition & 0 deletions docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ The root [README](../README.md) introduces Secure Tools. This directory owns det
| --- | --- |
| [Architecture](./architecture.md) | Static application structure, shared browser foundations, delivery, and future ecosystem direction |
| [Development workflow](./development-workflow.md) | Production, integration, Sprint, release, hotfix, merge-authority, and branch-cleanup rules |
| [TypeScript migration policy](./typescript-migration.md) | Strict incremental migration, JavaScript coexistence, and controlled browser emission |
| [Privacy model](./privacy-model.md) | Local-processing and network boundaries, storage, security controls, and bounded privacy claims |
| [Dependencies](./dependencies.md) | Production runtime inventory, versions, vendoring, licenses, and integrity ownership |
| [Local OCR foundation](./ocr-foundation.md) | Self-hosted Tesseract assets, languages, lifecycle, cancellation, caching, and privacy guarantees |
Expand Down
6 changes: 3 additions & 3 deletions docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

## Application model

Secure Tools is a static application built with semantic HTML, CSS, and Vanilla JavaScript ES Modules. It has no framework, Vite configuration, backend, database, authentication service, or runtime API. The build stages deployable files in `dist/`; a pinned npm preparation step reproduces and verifies the vendored OCR runtime without creating a server-side production dependency.
Secure Tools is a static application built with semantic HTML, CSS, and browser ES Modules. JavaScript and strict TypeScript coexist without a framework, Vite configuration, or bundler. It has no backend, database, authentication service, or runtime API. The build compiles an explicit list of TypeScript modules to ignored staging output, then stages deployable files in `dist/`; a pinned npm preparation step reproduces and verifies the vendored OCR runtime without creating a server-side production dependency.

Production routes load application code and pinned libraries from the same origin. File-processing workflows run through browser APIs and in-memory data. The [privacy model](./privacy-model.md) defines the limits of that statement.

Expand Down Expand Up @@ -59,9 +59,9 @@ Image conversion, resizing, and compression use browser decode, Canvas, and enco

## Development and delivery

Serving the generated `dist/` tree requires only an HTTP server. Reproducing OCR assets and running the full CI checks requires Node.js 24 and the exact lockfile. `npm run build` verifies prepared OCR assets and stages the site, `npm test` runs the static and unit suite, and `node tests/ocr-smoke.test.mjs` performs real English, Korean, and combined recognition.
Serving the generated `dist/` tree requires only an HTTP server. Reproducing OCR assets and running the full CI checks requires Node.js 24 and the exact lockfile. `npm run typecheck` enforces strict TypeScript contracts, `npm run build` verifies prepared OCR assets, compiles the declared TypeScript modules, and stages the site, `npm test` includes typechecking plus the static and unit suite, and `node tests/ocr-smoke.test.mjs` performs real English, Korean, and combined recognition. The incremental migration policy is documented in [TypeScript migration policy](./typescript-migration.md).

`.github/workflows/ci.yml` validates pull requests and pushes to `main` using Node.js 24. It installs the lockfile only to reproduce and verify OCR assets, then checks commit-range whitespace, JavaScript syntax, unit coverage, and real local OCR without adding deployment behavior.
`.github/workflows/ci.yml` validates pull requests and pushes to `main`, `v2`, and `v2.2` using Node.js 24. It installs the lockfile to reproduce and verify OCR assets and use the locked TypeScript compiler, then checks strict types, commit-range whitespace, JavaScript syntax, unit coverage, and real local OCR without adding deployment behavior.

Development uses short-lived branches and normal merge commits. Shared `main` history is not force-pushed or rewritten. GitHub Pages can publish `main` from the repository root; relative links support both the `/Secure_Tools/` project path and root-hosted deployments.

Expand Down
9 changes: 9 additions & 0 deletions docs/typescript-migration.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# TypeScript migration policy

Secure Tools adopts TypeScript incrementally within its existing static ES-module architecture. New shared and core browser modules should prefer TypeScript when explicit contracts improve safety. Existing JavaScript remains valid and should move only when a focused change benefits from typing; repository-wide rename-only migrations are out of scope.

TypeScript source uses strict mode. Run `npm run typecheck` before a pull request is merged. Browser TypeScript is compiled by `npm run compile:ts` into the ignored `.ts-build/` staging directory, then the static build copies only the declared modules to their established public JavaScript paths. Production builds do not include TypeScript sources, declaration files, or source maps.

Node build and release scripts may remain `.mjs`. Tests, locale catalogs, DOM-heavy page modules, and specialized PDF or image workflows may remain JavaScript until a bounded migration is useful. Vendored and generated third-party code, including Tesseract assets, is excluded from migration.

The module list in `scripts/typescript-modules.mjs` is the emission boundary. Add a browser module there only when its output path is stable and its consumers can continue importing JavaScript. This preserves JavaScript and TypeScript coexistence without a framework, bundler, runtime compiler, or Big Bang rewrite.
Loading
Loading