Skip to content

AI Code2Des — I/O Definition

SQS input

{
  "code2des_id": "019ffa75-01c0-75a2-8123-456789abcdf0",
  "page_import_id": "019ffa75-01c0-75a2-8123-456789abcdef",
  "attempt": 1,
  "nonce": "transport-fence",
  "organization_id": 1,
  "project_id": 7,
  "capture_url": "s3://bucket/1/7/page-import/.../capture.json",
  "capture_hash": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
}

Unknown fields are rejected. The worker verifies the exact capture bytes against capture_hash, then verifies the capture's Page Import and tenant identity. It never reads PostgreSQL or DocumentDB.

Deterministic spec

Code2DesSpec has spec_version: "1.0", mode: "exact", source viewport/URL/screenshot evidence, a root frame, and warnings. The discriminated node union is:

Node Important fields
frame bbox, fills/linear gradients, border, corner radii, shadow effects, clipping, blend mode, layout hint, children
text content, font family/size/weight, line height, letter spacing, color/opacity, alignment, decoration, single-line behavior
image content-addressed asset, object fit, optional saturation filter
vector inline SVG
unmatched source evidence plus deterministic reason

Every node carries layer_path, name, bbox, opacity, source node ID/tag, and absolute-placement evidence.

Artifacts and webhook

Artifacts live under {organization_id}/{project_id}/code2des/{code2des_id}/: result.json then manifest.json, or failed.json then failed-manifest.json. The successful result contains job IDs, capture hash, and spec. The manifest uses job_type: "code2des" and row_effects.code2des with status "1", result URL, and warning count. Failure uses status "2" and a safe error artifact.

The webhook includes type, job ID, attempt, nonce, terminal status, manifest URL, and schema version. The backend validates tenant prefix and identity before the attempt/status-guarded PostgreSQL update.

Plugin hydration

The public result API verifies that every referenced image asset remains under the Page Import tenant/job asset prefix and injects data_base64 for the plugin. The S3 URLs remain provenance; the plugin never receives S3 credentials.