Inspiration

Every modern software engineer has run into the frustration of debugging cryptic regular expressions, tracing silent data schema mismatches across microservices, or watching production nodes freeze due to catastrophic regex backtracking (Regular Expression Denial of Service / ReDoS).

Most existing testing tools are cluttered with ads, lack interactive visual breakdowns, or worse, transmit sensitive API payloads and regex strings to third-party servers. We built SpecGuard to solve this: an uncompromising, terminal-aesthetic developer cockpit that gives engineers an instant, visual X-ray into their pattern matching and data contract schemas—running 100% deterministically on the client with zero latency.


What It Does

SpecGuard combines two complementary verification pillars connected by an interactive Matrix-style gateway:

1. Regex Tracer & ReDoS Sentinel (The Red Pill)

  • Deterministic AST Tokenizer: Deconstructs complex ECMAScript regex patterns into syntax badges (character sets, quantifiers, anchors, lookarounds).
  • Match Inspector: Real-time extraction of named and indexed capture groups with zero-drift character-index highlighting.
  • ReDoS Safety Sentinel: Automated heuristic analysis flagging exponential and polynomial catastrophic backtracking hazards ((a+)+$) before they reach production.
  • Worker Sandboxing: Heavy regex evaluations execute in dedicated, non-blocking Web Workers with strict execution thresholds to guarantee zero browser freezes.

2. JSON Contract Diagnostic Suite (The Blue Pill)

  • Deep Schema Enforcement: Validates payloads against strict JSON Schema definitions in real time.
  • Multi-Fault Pinpointing: Detects enum mismatches, missing required keys in nested objects, out-of-bounds numbers, and unauthorized additional properties.
  • Actionable Remediation Guidance: Maps errors to precise line numbers with actionable fix instructions.

3. Developer Workflows

  • One-Click Presets & Sample Toggles: Built-in templates for SemVer, JWTs, ISO 8601 timestamps, and Webhook payloads, complete with instant Pass and Fail state buttons.
  • Instant Code Exporter: Compiles active validation schemas into ready-to-use TypeScript, JavaScript, and Python (pydantic / re) code snippets.

How We Built It

  • Core Architecture: Built with React, TypeScript, and Tailwind CSS.
  • Execution Engine: Evaluates pattern and schema rules using the browser's native V8 isolate—achieving sub-millisecond (<0.1ms) turnaround.
  • Zero-Backend Privacy: 100% client-side execution ensures sensitive API tokens, schemas, and proprietary payload structures never leave the developer's local browser memory.
  • Visual Design: Custom HTML5 Canvas digital rain shaders, high-contrast monospace typography, and a cyber-terminal dashboard.

Challenges We Ran Into

  • Safely Handling ReDoS in the Browser: Native JavaScript regex matching on exponential backtracking patterns immediately freezes the single main browser thread. We solved this by isolating runtime pattern evaluation in a timeout-enforced Web Worker thread.
  • Zero-Drift Highlighting: Rendering overlapping capture groups, lookahead assertions ((?=...)), and multi-line token streams without layout shift or desynchronized highlights required exact character-offset calculation logic.
  • Deterministic Multi-Error Diagnostics: Aggregating deep schema violations without failing early on the first encountered error required building a recursive AST-walking diagnostic formatter.

Accomplishments That We're Proud Of

  • Sub-0.1ms Engine Latency: Validation updates instantaneously with every keystroke.
  • Zero External API Dependencies: The entire application is self-contained and deploys as a static bundle without any third-party backend servers or cloud runtime costs.
  • Cohesive Identity: An intuitive developer tool disguised in an atmospheric terminal design.

What We Learned

  • Deep internals of the ECMAScript RegExp execution lifecycle and how recursive branch evaluation leads to exponential state explosions.
  • Techniques for building responsive, zero-latency developer tooling using Web Workers and deterministic schema parsing.

What's Next for SpecGuard

  • Adding support for OpenAPI 3.1 specifications.
  • Instant bi-directional schema inference (auto-generating Zod schemas and Pydantic models from live JSON payloads).
  • A standalone CLI tool for CI/CD pre-commit hooks.

Built With

Share this project:

Updates

Submission history