The path for listings without a [releases] section, and the only path for content hosted anywhere the watcher does not watch.
The checks do not trust the submitted document: download the archive from its download.url, recompute the hash, the sizes and the install root, re-run the dependency merge against the authored file, and reject the submission when any stamped field disagrees with what the check computed.
Exactly one new file, whose path and version do not exist yet.
Ownership and auto-merge work exactly as in the listing flow, KSAModding/content-index#4.
The path for listings without a
[releases]section, and the only path for content hosted anywhere the watcher does not watch.The checks do not trust the submitted document: download the archive from its
download.url, recompute the hash, the sizes and the install root, re-run the dependency merge against the authored file, and reject the submission when any stamped field disagrees with what the check computed.Exactly one new file, whose path and version do not exist yet.
Ownership and auto-merge work exactly as in the listing flow, KSAModding/content-index#4.