Files
toolbox-portal/README.md
T

50 KiB
Raw Permalink Blame History

add·ideas Toolbox Portal

toolbox-portal is the static launcher and release assembler for the add·ideas browser toolbox. Version 0.2.21 reads one same-origin catalogue, shows each app as a compact launch tile, and keeps personal pins, drag-and-drop ordering, visibility, and appearance in the current browser. Pinned tools have their own section; search, category, and clickable tag filters stay close to the tool list.

The v1 boundary is intentionally small:

  • apps remain separately versioned and released repositories;
  • @add-ideas/toolbox-contract owns manifest, catalogue, and URL validation;
  • the portal navigates to apps—there are no iframes, plugins, remote modules, or runtime-loaded application code;
  • the assembler copies already-built, exact ZIP artifacts and never builds app source or resolves a latest release.

Development

Requirements: Node.js 22 or newer and npm 11 or newer. The committed .npmrc selects the public, token-free package scope on Gitea; registry credentials are not required to install the Toolbox SDK packages. Install and verify the portal:

npm ci
npm test
npm run lint
npm run build
npm run dev

The package lock resolves the ^0.2.3 SDK ranges to the published 0.2.3 packages. A sibling SDK checkout is only needed when intentionally developing the SDK and portal together.

Vite uses base: './', so the built portal works at / or a nested static path. The development catalogue at public/toolbox.catalog.json points to assembled paths (./apps/pdf/, ./apps/xslt/, ./apps/onenote/, ./apps/av/, ./apps/regex/, ./apps/svg/, ./apps/auth/, ./apps/sudoku/, ./apps/colour/, ./apps/office/, ./apps/image/, ./apps/file/, ./apps/epub/, ./apps/archive/, ./apps/privacy/, ./apps/crypto/, ./apps/barcode/, ./apps/network/, ./apps/geo/, ./apps/helper/, ./apps/rand/, ./apps/data/, ./apps/diff/, ./apps/time/, ./apps/text/, and ./apps/unicode/). Those manifests will correctly appear as unavailable until an assembled release is being served.

Catalogue and launches

The portal fetches ./toolbox.catalog.json, validates it with the shared contract, and then validates each enabled manifest. A bad individual manifest is reported without hiding valid apps; a bad or unreachable catalogue gets a retry state. An empty valid catalogue gets its own empty state.

Internal launch links stay same-origin and receive the exact catalogue URL in a toolbox query parameter. For example:

/apps/pdf/?toolbox=https%3A%2F%2Ftoolbox.example%2Ftoolbox.catalog.json

Apps discover that context through the shared shell/contract and retain their standalone fallback when no context is present. External catalogue entries open according to their declared launch mode and do not receive toolbox context.

Personal settings use the namespaced local-storage key @add-ideas/toolbox-portal:v1:preferences. The preferences panel can reset, export, and import the versioned JSON document. The portal itself does not transmit preferences. Because Toolbox apps share an origin, code explicitly trusted in an app can access same-origin browser storage; review each app's privacy and executable-code warning. Light, dark, and system modes are supported.

Production deployment behind Traefik

The committed compose.yaml is the shortest production path. Its release container downloads the immutable Toolbox 0.18.1 ZIP during the image build, verifies SHA-256 before extracting it, and then copies only the verified static files into the pinned unprivileged nginx image. Node.js and a local portal assembly are not required on the deployment host.

Prerequisites:

  • Docker with the Compose plugin;
  • Traefik attached to the existing external Docker network internal;
  • Traefik HTTP and HTTPS entrypoints named web and websecure;
  • a certificate resolver named netcup;
  • DNS for toolbox.add-ideas.de and auth.toolbox.add-ideas.de pointing to that Traefik instance; and
  • outbound HTTPS access to git.add-ideas.de while the image is built.

Deploy a fresh clone with:

git clone https://git.add-ideas.de/lotobo/toolbox-portal.git
cd toolbox-portal
docker compose up -d --build
docker compose ps

No host port is published. Traefik permanently redirects http://toolbox.add-ideas.de to HTTPS, routes https://toolbox.add-ideas.de to nginx on the shared network at port 8080, and obtains its TLS certificate through netcup. The hostname, network, resolver, release version, and matching checksum can be overridden through environment variables; copy .env.example to .env only when an override is needed. For example, set TOOLBOX_HOST=staging.toolbox.add-ideas.de for a staging host.

The same container also exposes only the packaged authentication app at https://auth.toolbox.add-ideas.de/. Traefik adds the internal /apps/auth prefix while the public URL remains /, so assets remain relative and the browser binds WebAuthn credentials to the dedicated auth.toolbox.add-ideas.de RP ID. The main Toolbox copy at /apps/auth/ remains useful for offline inspection but disables live ceremonies because all Portal apps share that origin. The router hostname can be overridden with AUTH_TOOLS_HOST, but the bundled Auth Tools release enables live ceremonies only on its pinned production host (or localhost); other hosts remain inspect-only. A different production host therefore also requires rebuilding Auth Tools with the new exact host. Never widen the RP ID to add-ideas.de.

The external network is deliberately not created by this project. Creating a private project-local network would prevent an independently managed Traefik container from reaching the service.

Exact release assembly

Every app release ZIP must put these items at its archive root:

index.html (or the entry declared by toolbox-app.json)
toolbox-app.json
CHANGELOG.md
LICENSES/
SOURCE.md
...built static assets

The app release should also publish a matching .sha256 sidecar. The manifest must declare the pinned reverse-DNS id and version. Application and portal versions are independent.

release/toolbox.lock.json is the reviewed Toolbox v0.18.1 / Portal v0.2.21 lock. Its URLs and checksums pin the published PDF Tools 0.4.4, XSLT Tools 0.4.3, OneNote Tools 0.3.4, Audio & Video Tools 0.3.0, Regex Tools 0.4.2, SVG Tools 0.1.0, OTP & Passkey Tools 0.3.0, Sudoku Tools 0.2.1, Colour Tools 0.1.0, Office Tools 0.1.0, and the initial 0.1.0 releases of Image, File, EPUB, Archive, Privacy, Crypto, Barcode, Network, Geo, Helper, Random, Data, Diff, Time, Text, and Unicode Tools. Use release/toolbox.lock.example.json as the template for a future release and verify every downloaded asset before committing updated values. Artifacts may be:

  • a path relative to the lock file;
  • a file: URL; or
  • a credential-free HTTPS URL to an immutable release asset.

For a private Gitea release, download the exact asset first and put its local path in the lock. Do not put credentials in a lock URL.

Build the portal and assemble the distribution:

npm ci
npm test
npm run build
npm run assemble -- \
  --lock release/toolbox.lock.json \
  --portal-dist dist \
  --output build/toolbox \
  --archive build/add-ideas-toolbox-0.18.1.zip

Existing output is refused. Pass --force only when replacing those exact paths is intended. A successful run produces:

build/toolbox/
├── index.html
├── toolbox.catalog.json       generated from the lock
├── toolbox.release.json       ids, versions, targets, checksums
├── LICENSE.txt
├── SOURCE.md
├── THIRD_PARTY_LICENSES.txt
├── THIRD_PARTY_NOTICES.md
└── apps/
    ├── pdf/
    ├── xslt/
    ├── onenote/
    ├── av/
    ├── regex/
    ├── svg/
    ├── auth/
    ├── sudoku/
    ├── colour/
    ├── office/
    ├── image/
    ├── file/
    ├── epub/
    ├── archive/
    ├── privacy/
    ├── crypto/
    ├── barcode/
    ├── network/
    ├── geo/
    ├── helper/
    ├── rand/
    ├── data/
    ├── diff/
    ├── time/
    ├── text/
    └── unicode/

build/add-ideas-toolbox-0.18.1.zip
build/add-ideas-toolbox-0.18.1.zip.sha256

The assembler verifies SHA-256 before opening an artifact, validates every app manifest with @add-ideas/toolbox-contract, requires its id/version to equal the lock, and smoke-checks each declared entry, icon, and packaged manifest asset after extraction. It rejects insecure or credential-bearing redirects, HTTP, latest aliases, ZIP traversal, absolute paths, symlinks, special files, duplicate paths, oversized entries, and unsafe compression ratios. Canonical path checks protect source and output trees even through symlink aliases, and publication rolls all outputs back if a staged rename fails. Artifacts are unpacked only under apps/<locked-target>. The assembler never runs artifact content.

The archive writer sorts file names and fixes ZIP timestamps and modes so the same assembled directory produces stable bytes. To package an already assembled directory separately:

npm run package:static -- \
  --input build/toolbox \
  --output artifacts/add-ideas-toolbox-0.18.1.zip

This also emits a .sha256 sidecar.

Local assembled container and publication

Containerfile serves only the assembled files with unprivileged nginx on port 8080. It adds restrictive browser headers, same-origin isolation, explicit application/javascript for .mjs engine modules and application/wasm, immutable caching only for Vite-hashed assets and narrowly matched semver-versioned FFmpeg core files, and revalidation for all other files. The opaque-origin SVG preview iframe loads its packaged controller with a URI-exact CORS and cross-origin resource-policy exception; all other files retain the same-origin policy and every normal security header. Camera access is denied by default. It is granted to the dedicated auth.toolbox.add-ideas.de origin and, on the shared Toolbox host, only to /apps/barcode/; both apps still request it only after an explicit user action. If AUTH_TOOLS_HOST is customized, update the exact host entry in deploy/nginx.conf and Auth Tools' pinned WebAuthn host at the same time. Every Toolbox app, including Random Tools, is constrained to same-origin connections. Random Tools implements its random generators locally with browser APIs and never calls a third-party randomness service.

The packaged policy intentionally does not grant CSP unsafe-eval. SaxonJS's ixsl:eval() extension is therefore unsupported in this deployment profile; normal local XML/XSLT transformations do not require that permission.

Assemble first, then:

podman build -f Containerfile \
  -t git.add-ideas.de/lotobo/toolbox:0.18.1 .
podman run --rm -p 8080:8080 \
  git.add-ideas.de/lotobo/toolbox:0.18.1

For a direct-port local deployment after assembly, use the separate example:

docker compose -f compose.example.yaml up -d --build

Publish both common architectures from a buildx-enabled workstation or Gitea runner:

docker login git.add-ideas.de
docker buildx build \
  --platform linux/amd64,linux/arm64 \
  --file Containerfile.release \
  --tag git.add-ideas.de/lotobo/toolbox:0.18.1 \
  --tag git.add-ideas.de/lotobo/toolbox:0.18 \
  --push .

The default unprivileged nginx image is the security-fixed 1.31.3-alpine baseline pinned to its reviewed multi-architecture digest. Re-resolve and review that digest whenever the base image is upgraded, then record it in the release notes.

Manual Gitea publication checklist

No credentials belong in this repository. The publishing workstation or runner needs permission to push code, releases, and container packages to lotobo/toolbox-portal.

  1. Run npm ci, npm test, npm run lint, and npm run build from a clean checkout of the intended portal tag.
  2. Publish each app's versioned ZIP, .sha256, toolbox-app.json, changelog, and licence notices in its own Gitea release.
  3. Verify downloaded app assets with sha256sum -c <asset>.sha256; copy those exact values into a reviewed toolbox lock.
  4. Run the assembler and serve build/toolbox from a nested test path. Open all 26 apps, switch between them, and confirm the encoded toolbox context.
  5. Verify the distribution with (cd build && sha256sum -c add-ideas-toolbox-0.18.1.zip.sha256).
  6. Commit the reviewed lock, tag the toolbox release (for example v0.18.1), and push the branch and tag to Gitea.
  7. In Gitea, open Releases → New release, select the tag, and upload the static ZIP plus its .sha256 file. Do not use a mutable “latest” URL in a future lock.
  8. Build and push the AMD64/ARM64 OCI image as shown above. Record the resulting multi-architecture manifest digest in the release notes.

For Gitea Actions, store registry credentials as repository secrets, check out the exact tag, install with npm ci, run the same verification/assembly commands, and upload only the already-created ZIP/checksum and OCI image. The workflow must not re-resolve app versions or substitute a newer release.

Existing tools

Tool State and boundary Principal workflows Important concrete scope Critical considerations and integrations
pdf-tools Existing; dedicated repository Merge, split, reorder, rotate and export PDF pages Thumbnail workspace; multi-document operations; ZIP and PDF output; saved local workspace Workers and IndexedDB; large-document memory control; future signature inspection through crypto-tools; metadata and safe-sharing through privacy-tools
xslt-tools Existing; dedicated repository Develop, test and run XSLT transformations XML/XSLT editors; transformation results; local files; saved projects; validation and diagnostics Lazy SaxonJS loading; relocatable assets; useful handoffs to data-tools, schema-tools and diff-tools
onenote-tools Existing rich-reader release; dedicated repository Open, browse, inspect and export OneNote sections and packages locally Desktop/unfragmented FSSHTTPB .one/.onetoc2; none/LZX/MSZIP/Quantum and multi-cabinet .onepkg; trees, rich text, images, tables, ink, attachments and export Native TypeScript worker with no Wasm; bounded parsing, rendering and export; fragmented FSSHTTP fails safely; no editing or pixel-perfect fidelity
av-tools Existing local-first v0.3.0 release; dedicated repository Convert and lightly edit audio and video locally in the browser Immediate native playback and basic file information; progressive stream inspection on demand; quick conversion; trim, split and crossfade concatenate; crop, resize, normalize, fades, waveform, metadata, chapters, subtitles, scene thumbnails/contact sheets, presets and export Reviewed ffmpeg.wasm 0.12.10 ST/MT build with verified Opus and bundled label font; bounded queue, temporary storage and resource policy; isolation enables MT with automatic ST fallback; versioned core assets are immutable
regex-tools Current local-first v0.4.2 release; dedicated repository Develop, explain, test and apply JavaScript, PCRE2, PHP, Perl, Python, Ruby, Java, C++, Go, .NET, Rust and Scala/JVM-compatible regular expressions Deterministic syntax trees; engine-native matching, captures and bounded replacement; stable double-buffered live results; PCRE2 tracing and C17 generation; comparison; corpus apply; tests; risk/growth/benchmark analysis; generated cases; bounded minimization; validated ECMAScript formatting; project import/export and optional local persistence Open-source regexpp and pinned local WebAssembly runtimes for PCRE2, PHP preg, legacy Perl, CPython, CRuby, TeaVM Java/Scala compatibility, libc++ C++, Go, .NET and Rust in killable workers; explicit source/licence inventories, resource limits and engine-specific offset semantics
svg-tools Initial local-first v0.1.0 release; dedicated repository Inspect and edit SVG source, structure, geometry, references and accessibility locally Synchronized source/tree/canvas/inspector; path and transform tools; reference analysis; optimization; CSS animation preview; exact, sanitized, raster and project export Untrusted SVG is sanitized into an opaque-origin sandbox; bounded parsing and decompression, explicit security findings and a URI-scoped controller header exception; later milestone slices remain intentionally tracked in the app repository
auth-tools Current local-first v0.3.0 release; dedicated repository Generate, migrate and diagnose OTP credentials, and inspect, verify and test WebAuthn/passkey ceremonies locally HOTP/TOTP/OCRA with time travel, resynchronization and rotation planning; QR, Google, Aegis and encrypted PSKC migration; WebAuthn extension experiments and replayable traces; assertion, attestation, signer-chain and historical metadata-policy evaluation Authentication material remains memory-only unless explicitly exported; redaction is deliberate but not a secrecy guarantee; live ceremonies and camera scanning are enabled only at the exact dedicated auth.toolbox.add-ideas.de origin, while the shared Portal path remains inspect-only; no raw CTAP administration
sudoku-tools Current local-first v0.2.1 release; dedicated repository Set, play, generate, analyse and solve classic, Killer and rich variant Sudoku locally 4×416×16 grids; registry-backed constraint packs including cages, lines, dots, XV, inequalities, indexing and Fog of War; staged hints, candidate maintenance, advanced logical techniques, setter quality checks, mixed-variant generation, source-preserving f-puzzles/SudokuPad interoperability, autosave recovery and searchable local projects Worker-bounded solving, generation and quality analysis; strict inert imported-visual validation; fog-safe play assistance; IndexedDB history with memory fallback; stable workspace geometry, responsive zoom and pan, a 3×3 standard keypad, tap selection, patterned colours, accessibility controls and an offline-capable PWA shell
colour-tools Initial local-first v0.1.0 release; dedicated repository Convert, composite, interpolate, pick, sample, analyse and export colours locally General colour conversion; arbitrary RGBA compositing; multi-stop colour steps; large visual and native pickers; local image sampling and palette extraction; contrast, gamut and colour-vision-deficiency analysis; harmonies and design-token export Processing and image access remain local; colour spaces, encoded versus linear-light compositing, interpolation and gamut-mapping assumptions are explicit; mathematical conversion is distinguished from display simulation; integrates with SVG, image and token tools
office-tools Initial local-first v0.1.0 read-only release; dedicated repository Open and view word-processing documents, spreadsheets and presentations locally DOCX, XLSX and PPTX plus ODT, ODS and ODP; document, sheet and slide views with search, outline or thumbnail navigation and zoom; text, tables, images, styles, metadata, cached formula values and presentation notes Bounded worker-based inert package and XML parsers never execute macros, scripts, formulas, active content or external resources; legacy binary DOC, XLS and PPT are unsupported; viewing is intentionally read-only and does not promise pixel-perfect Office-suite layout fidelity
image-tools Initial local-first v0.1.0 release; dedicated repository Inspect, crop, rotate, resize, compare and batch-convert raster images locally Static JPEG, PNG and WebP; bounded queues; aspect presets; fit/fill/exact resize; PNG/JPEG/WebP export; per-result operation reports Animated and multi-picture inputs are inspect-only; canvas re-encoding does not preserve arbitrary metadata, ICC profiles, HDR precision or byte identity
file-tools Initial local-first v0.1.0 release; dedicated repository Identify, inspect, hash and inventory local files Signature and claimed-MIME comparison; paged hex/ASCII and string views; SHA-256/SHA-512; deterministic JSON/CSV manifests; duplicate candidates Detection and entropy are heuristics rather than validation or malware analysis; v0.1 intentionally does not mutate, split, join or rename files
epub-tools Initial local-first v0.1.0 release; dedicated repository Read, inspect, validate and repair EPUB 2/3 publications Package, metadata, spine, EPUB 3 nav and EPUB 2 NCX views; sandboxed reading; link checks; metadata and cover editing; text/chapter/report export; normalized rebuilds Strict bounded ZIP and XML handling; active and external content are blocked; DRM is detected but never bypassed; focused preflight is not a complete EPUBCheck implementation
archive-tools Initial local-first v0.1.0 release; dedicated repository Inspect, create, compare and safely extract archive content ZIP/ZIP64, TAR/USTAR/PAX, gzip and tar.gz; inert previews; deterministic ZIP/TAR output; cross-format inventory comparison; selected-file repackaging Path, entry-count, expanded-size and compression-ratio limits; no direct filesystem restoration, nested expansion, encrypted or multipart ZIP support; links and special entries are blocked
privacy-tools Initial local-first v0.1.0 release; dedicated repository Inspect image metadata and make independently verified sharing copies Deep JPEG, PNG and WebP scans for EXIF/IPTC/XMP/profiles/previews/provenance and trailing data; orientation-normalized pixel re-encoding; source/output hashes; JSON and ZIP reports Not an anonymity guarantee; static supported images only; re-encoding can change pixels and remove colour, resolution and authenticity information; reports can themselves contain sensitive metadata
crypto-tools Initial local-first v0.1.0 inspection release; dedicated repository Inspect certificate, request, revocation-list, key and JWK material Bounded PEM/DER X.509, CSR and CRL inspection; public/private key identification; JWK/JWKS warnings and RFC 7638 thumbprints; explicit issuer-signature links; DNS SAN hostname checks No browser/OS trust implication, complete RFC 5280 path validation, revocation service, issuance, key generation, private-key decryption or general signature verification
barcode-tools Initial local-first v0.1.0 release; dedicated repository Generate and decode QR codes and common barcodes SVG QR, Data Matrix, PDF417, Aztec and selected linear formats; bounded image or opt-in camera decode; structured QR payloads; CSV batch ZIP; GTIN and quiet-zone assistance Decoded payloads remain inert text and are never opened automatically; camera is path-scoped and user initiated; generated output, GS1 allocation and print quality still require applicable interoperability checks
network-tools Initial offline v0.1.0 release; dedicated repository Calculate IP networks and construct or inspect common network values IPv4/IPv6 canonicalization and CIDR ranges; URL/query parsing without navigation; DNS-record construction; response-header inspection; CSP builder; MIME reference Performs no DNS, URL, HTTP or scanning request; pasted values remain bounded and inert; results are construction and calculation aids rather than live network observations
geo-tools Initial local-first v0.1.0 release; dedicated repository Inspect, convert, simplify and analyse geospatial files GeoJSON, GPX, KML and coordinate CSV; WGS 84 bounds, distance and elevation; DouglasPeucker simplification; decimal/DMS conversion; coordinate-only sketch Small Point/LineString/Polygon model with scalar properties; conversion losses are explicit; no CRS transformation, basemap request or survey-grade claim
helper-tools Initial v0.1.0 app and reusable package release Encode, convert, inspect and calculate with shared bounded primitives Base/byte/text/URL conversion; Unicode and line transforms; exact number and unit conversion; hashes; CIDR; timestamps; hardened JSON/CSV; secure and seeded random primitives; deep-linked calculator workspaces Framework-free @add-ideas/toolbox-helpers package is consumed directly by eleven v0.1 apps; operations disclose strictness, limits and non-cryptographic seeded boundaries
rand-tools Local-only v0.1.1 release; dedicated repository Generate secure or reproducible random values through focused workspaces Unbiased WebCrypto integers/strings; seeded reproducible generation; UUIDv4/v7 and ULID; dice; sampling, shuffle, passphrases and normal distribution; all generators run entirely in the browser Secure local generation never falls back; deterministic output is reproducible rather than secret; the app makes no third-party randomness request and the Portal grants it no external network destination
data-tools Initial local-first v0.1.0 release; dedicated repository Inspect, format, query, flatten and convert structured data JSON, YAML 1.2, TOML, XML, CSV, TSV and NDJSON; exact JSON numbers; bounded tree/table/leaf views; JSON Pointer and safe path queries; all-format conversion with loss/coercion reports; spreadsheet-formula neutralization Disposable bounded parser worker; rejects active XML constructs and unsafe object keys; conversions surface information loss and round-trip instability
diff-tools Initial local-first v0.1.0 release; dedicated repository Compare text, JSON, XML and delimited data semantically Line/word/code-point/grapheme text diff; exact newline state; object-aware exact-number JSON and RFC 6902; namespace-aware XML rules; keyed CSV/TSV; unified/side-by-side views and portable reports Normalization settings and ignored distinctions remain visible; bounded disposable worker; v0.1 intentionally excludes images, binary documents, directories and archives
time-tools Initial local-first v0.1.0 release; dedicated repository Convert timestamps and explore zones, arithmetic and recurrence Exact signed nanosecond epochs; IANA-zone comparisons and DST ambiguity; wall-clock versus elapsed arithmetic; bounded cron and RRULE previews; business days; escaped UTC ICS export Uses the browser's IANA data and does not model leap seconds; regional holidays are never inferred; recurrence and skipped/ambiguous local-time choices are explicit
text-tools Initial local-first v0.1.0 release; dedicated repository Build ordered, inspectable plain-text transformation pipelines Line endings, trimming, whitespace, sort/deduplicate, locale case, Unicode normalization, transliteration, escapes, wrapping, columns, explicit file decoding and versioned recipes Exact source/result and per-step changes stay visible; compatibility normalization, transliteration, narrow encodings and selected transforms warn when they may be lossy
unicode-tools Initial local-first v0.1.0 release; dedicated repository Search and inspect Unicode characters, emoji, scripts, text and confusables Checksum-pinned Unicode 17.0 catalogue; character/alias/code-point search; emoji and named sequences; UTF-8/UTF-16/escape inspection; grapheme segmentation; normalization; UTS #39 skeleton; selected Unihan fields; symbol collections Official Unicode data is redistributed under Unicode-3.0 and is not scraped from symbol sites; private-use and surrogate ranges are not misrepresented as assigned characters; confusable and mixed-script results are review signals, not security verdicts

Planned tools

Tool State and boundary Principal workflows Important concrete scope Critical considerations and integrations
flow-tools Later platform layer Compose local processing operations across tools Example: CSV → filter → QR generation → SVG template → PDF → ZIP; reusable recipes; typed inputs and outputs; progress and cancellation Do not load complete React applications into one runtime; expose separate worker-safe operation packages only after several apps have stable operations
subtitle-tools Medium priority; dedicated repository Edit, validate and synchronize captions SRT, WebVTT and ASS; timing shifts; stretching; frame-rate conversion; overlap and reading-speed checks; waveform synchronization; revision comparison Direct integration with av-tools; preserve style information when supported and disclose conversion losses
midi-tools Medium specialist app MIDI event inspection and editing; transpose, quantize, tempo maps and controller data; device access should remain optional
3d-tools Large specialist app Inspect STL, OBJ and glTF; dimensions, bounding boxes, mesh simplification and common geometry defects; worker/GPU use and file limits
query-tools High-value but large; dedicated repository Analyse local tabular and relational data with SQL CSV, JSON, NDJSON, Parquet and SQLite; schema inference; joins; aggregation; pivots; charts; export to common data formats WASM memory and streaming; distinguish this analytical product from document-oriented data-tools; query work must remain local
scan-tools Large app Camera/document correction; crop, deskew and threshold; page assembly; local OCR; PDF output; model downloads and memory use must be explicit
package-tools Medium priority Inspect compound and package-based formats EPUB; DOCX/XLSX/PPTX; ODF; JAR; APK; browser extensions; package trees; manifests; relationships; embedded media; signatures; orphaned parts Generic container inspector with format adapters; complements rather than replaces onenote-tools, epub-tools and office-tools
label-tools Medium priority; dedicated repository Generate labels and badges from templates and data CSV/JSON merge into SVG templates; QR/barcode fields; serial numbers; A4 label sheets; badges; asset tags; cut marks; calibration Strong suite demonstration linking data, SVG, barcode, random and PDF capabilities; print dimensions must be explicit and testable
font-tools Medium priority; dedicated repository Inspect, preview and prepare fonts Glyph coverage; variable axes; metadata; fallback comparison; subsetting; CSS generation; arbitrary-text previews Font licensing and embedding restrictions must be visible; use untrusted-font isolation and strict parser limits
fixture-tools Medium priority Generate deterministic test data JSON Schema, XSD, SQL DDL, CSV headings or interactive models to JSON, CSV, XML, SQL and NDJSON; foreign keys; distributions; boundary and invalid cases Seeded reproducibility; uniqueness constraints; privacy-safe synthetic data; natural extension of rand-tools
minimize-tools Distinctive specialist tool Reduce a failing input while preserving a failure Minimize XML triggering an XSLT error; shortest regex pathological input; smallest JSON schema failure; selectable failure predicates Expensive repeated execution must be bounded and cancellable; record the exact predicate and transformation versions
format-lab Later, distinctive product Explore conversion paths and information loss Format graph; round-trip tests; property preservation; type coercion; metadata loss; recommended path selection across data, image, AV and subtitle formats No conversion should be described as lossless without testing relevant properties
repro-tools Medium-to-later Create manifests and provenance records File hashes; directory manifests; operation history; tool/version/parameter records; deterministic package creation; verification reports Useful foundation for reproducible workflows and signed manifests; integrates with crypto, archive and flow tools
schema-tools Dedicated specialist app Validate, inspect and generate examples for JSON Schema, XSD, Relax NG, Schematron and OpenAPI; visualize references and incompatibilities
log-tools Dedicated app Stream and filter large logs; parse common formats; correlate records; build timelines; extract fields; anonymize values; avoid loading the complete file into memory
binary-tools Dedicated specialist app Base64, hexadecimal, CBOR, MessagePack, ASN.1 and Protocol Buffers; schema-assisted decoding; byte-range highlighting; strict depth and size limits
git-tools Small-to-medium app Patch inspection and editing; .gitignore testing; semantic-version comparison; conventional commits; changelog normalization; no repository-hosting dependency
api-tools Medium app OpenAPI validation; request and response examples; curl and client-command generation; saved HTTP-exchange inspection; direct browser requests remain subject to CORS
mail-tools Medium app EML and MIME inspection; header analysis; attachment extraction; body-part comparison; HTML mail must be heavily sandboxed
calendar-tools Small-to-medium app ICS inspection, merging, deduplication, repair, recurrence visualization and timezone diagnostics
contact-tools Small-to-medium app vCard inspection and editing; CSV mapping; deduplication; contact QR generation; treat all contact data as sensitive
diagram-tools Medium app Code and visual editing for Mermaid, Graphviz and related representations; renderers require sanitization and sandboxing
token-tools Small-to-medium app Design-token editing and conversion between JSON, CSS custom properties, Sass, Android and iOS forms; integrate with colour and SVG tools
device-tools Specialist app Serial terminal, sensor logger, microcontroller console and controlled firmware installation; explicit permission and browser-capability checks

Licensing

Portal source is AGPL-3.0-only; see LICENSE. The contract is Apache-2.0, and each assembled application retains its own licence and notices. An assembled ZIP/container is an aggregate of those independently licensed components; see THIRD_PARTY_NOTICES.md and each apps/<slug>/LICENSES/ directory.