mirror of
https://github.com/zapstore/zapstore.git
synced 2026-10-05 20:48:24 +00:00
- Rename specs/ to spec/ (singular) - Consolidate templates into single _TEMPLATE.md files with examples - Add "When to Create a Feature Spec" and work lifecycle to QUALITY_BAR.md - Document package manager as FEAT-001 (first behavioral contract) - Remove old _template/ directories
47 lines
1.6 KiB
Markdown
47 lines
1.6 KiB
Markdown
# Zapstore — Invariants
|
|
|
|
The following guarantees are non-negotiable.
|
|
If any invariant is violated, the implementation is incorrect.
|
|
|
|
## UI Safety
|
|
|
|
- UI rendering must remain responsive under partial or total network failure.
|
|
- The UI must never block on I/O, cryptography, disk access, or network/relay operations.
|
|
- All background or asynchronous work must be cancellable and lifecycle-safe.
|
|
- Local data must be sufficient to render meaningful UI state; network access must enhance UX, not gate it.
|
|
- No operation may assume continuous network availability.
|
|
|
|
## Async Discipline
|
|
|
|
- No polling or artificial delays (e.g., Future.delayed for timing).
|
|
- Background work must surface results asynchronously and non-blockingly.
|
|
- All async work must be cancellable.
|
|
|
|
## Local-First Guarantees
|
|
|
|
- Cached data must be preferred over network data when available.
|
|
- Installed apps and metadata must be accessible offline.
|
|
- Network failures must degrade gracefully.
|
|
|
|
## Security & Verification
|
|
|
|
- APKs must never be installed unless their hash matches the expected value.
|
|
- Signed Nostr events must be verified before use.
|
|
- NWC secrets must be stored securely and must never be logged or exposed.
|
|
|
|
## Data Robustness
|
|
|
|
- Parsing unknown, missing, or future tags must not crash the app.
|
|
- Partial or invalid data must degrade gracefully.
|
|
|
|
## Lifecycle Safety
|
|
|
|
- Subscriptions must always be cancellable.
|
|
- Isolates and background jobs must not leak resources.
|
|
- Reconnection or retries must not duplicate events or actions.
|
|
|
|
## UX Safety
|
|
|
|
- All user-visible processes must have explicit states (loading, empty, success, error).
|
|
- Silent failures are unacceptable.
|