Skip to content
Novus Examples
webmanifest540 B

Web app manifest whose start_url is outside its scope (deliberately invalid)

A deliberately invalid manifest: start_url sits at /dashboard/ while scope is /app/, and a shortcut points at another origin entirely. Both are the kind of mistake that makes an installed app open in a browser tab. For testing scope-containment validation.

Preview — first 28 lineswebmanifest
{
  "name": "Example Scope Mismatch",
  "short_name": "OutOfScope",
  "id": "/app/?src=scope",
  "start_url": "/dashboard/?src=scope",
  "scope": "/app/",
  "display": "standalone",
  "theme_color": "#059669",
  "icons": [
    {
      "src": "/icons/icon-192.png",
      "sizes": "192x192",
      "type": "image/png"
    },
    {
      "src": "/icons/icon-512.png",
      "sizes": "512x512",
      "type": "image/png"
    }
  ],
  "shortcuts": [
    {
      "name": "Settings",
      "url": "https://other.example.org/settings"
    }
  ]
}

Specifications

Seed
70400
Site
example.com (fictional)
Format
W3C Web App Manifest
Scope
/app/
Start Url In Scope
false
Cross Origin Shortcut
true
Deliberately Invalid
true

Testing contract

Expected to fail
Scenario
Validate start_url, id and shortcut URLs against the declared scope.
Expected result
start_url is reported out of scope and the install is refused or start_url is coerced to the scope root; the cross-origin shortcut is dropped rather than registered.

What is a .webmanifest file?

A web app manifest (.webmanifest) is a JSON file that describes a Progressive Web App to the browser, declaring its name, icons, theme colors, start URL, and display mode. It enables installation to a device home screen and standalone launching. It is linked from HTML via a manifest link element.

How to use this file

Use an example webmanifest to test PWA installability, manifest JSON parsing, icon and display-mode handling, and browser or auditing tools like Lighthouse.

How to use this file for testing

“Web app manifest whose start_url is outside its scope (deliberately invalid)” is a deterministic Novus Examples fixture for Web assets, JSON parsing, Schema validation. Favicons, web app manifests, service workers, robots and sitemap files, Open Graph images, and .well-known resources — for testing web tooling, crawlers, PWA installers, and asset pipelines.

Documented properties for this file: seed 70400 · W3C Web App Manifest. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

Web-platform fixtures are standards-compliant samples against fictional example.com data. Test crawlers, PWA installers and manifest validators, favicon/icon pipelines, service-worker registration, or .well-known parsers against the documented structure.

Generated by generation/web_p7.py. Free for any use, no attribution required — license.