All skills
wix avatar

/wix-app

@dc6f1fa official
by Wix.comwix/skills33 stars
33

Build and review Wix CLI app extensions — dashboard pages, modals, plugins, menu plugins, custom element widgets, Editor React components, site plugins, embedded scripts, backend APIs, backend events, service plugins, data collections, and App Market readiness. Use when building ANY feature or extension for a Wix CLI app or preparing a Wix app for App Market review. Triggers on: add, build, create, implement, help me, dashboard, widget, plugin, backend, API, event, collection, embedded script, service plugin, Editor React component, checkout, shipping, tax, discount, SPI, CMS, schema, tracking, popup, admin panel, menu item, modal, validate, test, verify, register extension, App Market, app review, submission readiness.

Use this Skill: https://skilld.dev/gh/wix/skills/wix-app

This session only. Nothing lands on disk.

referencesservice-pluginREALTIME-PERMISSIONS.md

≈755 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Realtime Permissions Provider Service Plugin Reference

Overview

The Realtime Permissions Provider SPI controls who can receive messages on your app's Wix Realtime channels. When a subscriber from another app attempts a cross-app subscription to one of your channels, Wix calls your checkSubscriberPermissions handler and waits synchronously for the answer. Without a registered provider, Wix denies all cross-app subscription attempts by default.

This is the only SPI outside eCommerce and Bookings — it belongs to the Realtime module.

Request and Response Schema

Before implementing, call ReadFullDocsMethodSchema on the docs URL to get the full request/response types.

Handler Docs URL
checkSubscriberPermissions https://dev.wix.com/docs/sdk/core-modules/realtime/extensions/realtime-permissions-provider/check-subscriber-permissions

The request gives you the channel (name + optional resourceId), the subscriber (type: ADMIN / MEMBER / VISITOR, and _id), and requestingAppId (the app attempting the subscription, may be empty). Return { read: true } to allow, { read: false } to deny.

Example: Allow Members and Admins, Deny Visitors

import { realtimePermissionsProvider } from "@wix/realtime/service-plugins";

realtimePermissionsProvider.provideHandlers({
  checkSubscriberPermissions: async (payload) => {
    const { request } = payload;
    const { subscriber, channel } = request;

    if (channel?.name === "public-updates") {
      return { read: true };
    }

    return { read: subscriber?.type !== "VISITOR" };
  },
});

Key Implementation Notes

  1. The generated stub may include a write field — remove it. wix generate for this pluginType has been observed scaffolding a response of { read: true, write: false }, but CheckSubscriberPermissionsResponse only has read?: boolean. Confirm against the installed @wix/auto_sdk_duplexer_realtime-permissions-provider types if tsc doesn't catch it for you.
  2. channel and subscriber are both optional on the request — channel?: Channel, subscriber?: Subscriber. Accessing .name/.type without the ?. above fails tsc with "possibly undefined."
  3. Deny with data, not errors — return { read: false } for normal policy denials. Only throw InvalidArgumentError when the request itself is invalid or missing data; any other thrown error, timeout, or unreachable service makes Wix deny the subscription with a 503.
  4. Respond quickly — the call is synchronous and blocks the subscription attempt; a slow handler delays it, and a non-responsive one causes a 503 denial.
  5. Be consistent — the same channel, subscriber, and context should always yield the same decision.
  6. No provider means no cross-app access — until you implement this SPI, all cross-app subscription attempts to your channels are denied by default.

Source: SKILL.md on GitHub

1 warningtoday4 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    This skill is a specialized development toolkit for building extensions on the Wix platform. It provides comprehensive instructions for creating dashboard pages, backend APIs, and site plugins using the Wix CLI and SDKs. No malicious patterns were detected; the skill's behaviors, such as dependency management, command execution for builds, and local script execution for code reviews, are entirely consistent with its purpose as a developer productivity tool for the Wix ecosystem.

  • Sockettoday

    1 alert: gptAnomaly

  • Snyktoday

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at dc6f1fa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated yesterday
compatibility
requires `@wix/cli` >= 1.1.192.

README badge

README badge for wix/skills/wix-app

Builds dashboard pages, modals, plugins, custom widgets, Editor React components, backend APIs, events, service plugins, and data collections for Wix CLI apps. Provides decision logic, API patterns, and validation workflows; scaffolding is owned by the Wix CLI via `wix generate --params`.

Generated from the current SKILL.md.

What extension types does this skill cover?
All Wix CLI app extension types: dashboard pages, modals, plugins, menu plugins, custom element widgets, Editor React components, site plugins, embedded scripts, backend APIs, backend events, service plugins, and data collections.
Does this skill scaffold the extension files for me?
The Wix CLI owns scaffolding via `wix generate --params` for all extension types except Backend API. This skill provides decision logic, API guidance, and business-logic patterns to fill in the generated stubs. Backend API files must be created manually.
What Wix CLI version is required?
The skill requires @wix/cli >= 1.1.192.
Do I need to create a Data Collection extension for app-specific data?
Yes, if you're saving or persisting app-specific data, managing domain entities in a dashboard, or running a service plugin that reads app-configured data. The skill infers this automatically—you don't need to explicitly request it.
Does this skill cover Wix Stores API usage?
Yes. When using any Wix Stores API (products, inventory, orders), the skill requires dual V1/V3 catalog support and references the Stores Versioning guide for module selection and field mapping.

Generated from the current SKILL.md. These answers refresh after source changes.