pixellint

Adcanvas CSC events carry SDK context and base36 telemetry.

The public NEXD tracking SDK supplies party, session, page-view and ad context on its csc-event image URL. Numeric telemetry uses base36, including signed and fractional values.

The SDK truncates its page location by UTF-16 code units. Proprietary mincode event data and checksum correctness remain outside this pack.

Apply the contracts within their published source scope.

The SDK truncates its page location by UTF-16 code units. Proprietary mincode event data and checksum correctness remain outside this pack.

What this pack matches

Hosts
analytics.adcanvas.com
Paths
/csc-event
Vendor docs
media.adcanvas.com/tracking.js

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
p recommended Party identifier emitted by the public SDK. IDs and custom event names are opaque; these are producer advisories, not a published rejection schema. vendor.adcanvas-csc.param.p.missing
vendor.adcanvas-csc.param.p.empty
docs
s recommended Session identifier emitted by the public SDK. IDs and custom event names are opaque; these are producer advisories, not a published rejection schema. vendor.adcanvas-csc.param.s.missing
vendor.adcanvas-csc.param.s.empty
docs
v recommended Page-view identifier emitted by the public SDK. IDs and custom event names are opaque; these are producer advisories, not a published rejection schema. vendor.adcanvas-csc.param.v.missing
vendor.adcanvas-csc.param.v.empty
docs
t recommended Arbitrary event type emitted by the public SDK. IDs and custom event names are opaque; these are producer advisories, not a published rejection schema. vendor.adcanvas-csc.param.t.missing
vendor.adcanvas-csc.param.t.empty
docs
a recommended Ad identifier emitted by the public SDK. IDs and custom event names are opaque; these are producer advisories, not a published rejection schema. vendor.adcanvas-csc.param.a.missing
vendor.adcanvas-csc.param.a.empty
docs
e recommended Per-page event identifier emitted by the public SDK. IDs and custom event names are opaque; these are producer advisories, not a published rejection schema. vendor.adcanvas-csc.param.e.missing
vendor.adcanvas-csc.param.e.empty
docs
c optional Milliseconds timestamp is serialized with Number.toString(36) by the public SDK; fractional base36 is allowed. This check concerns finite numeric producer values. vendor.adcanvas-csc.param.c.empty
vendor.adcanvas-csc.param.c.invalid
docs
i optional Available screen width is serialized with Number.toString(36) by the public SDK; fractional base36 is allowed. This check concerns finite numeric producer values. vendor.adcanvas-csc.param.i.empty
vendor.adcanvas-csc.param.i.invalid
docs
j optional Available screen height is serialized with Number.toString(36) by the public SDK; fractional base36 is allowed. This check concerns finite numeric producer values. vendor.adcanvas-csc.param.j.empty
vendor.adcanvas-csc.param.j.invalid
docs
k optional Device pixel ratio is serialized with Number.toString(36) by the public SDK; fractional base36 is allowed. This check concerns finite numeric producer values. vendor.adcanvas-csc.param.k.empty
vendor.adcanvas-csc.param.k.invalid
docs
w optional Viewport width is serialized with Number.toString(36) by the public SDK; fractional base36 is allowed. This check concerns finite numeric producer values. vendor.adcanvas-csc.param.w.empty
vendor.adcanvas-csc.param.w.invalid
docs
h optional Viewport height is serialized with Number.toString(36) by the public SDK; fractional base36 is allowed. This check concerns finite numeric producer values. vendor.adcanvas-csc.param.h.empty
vendor.adcanvas-csc.param.h.invalid
docs
n optional The public SDK encodes new-party and new-session states as t or f. vendor.adcanvas-csc.param.n.empty
vendor.adcanvas-csc.param.n.invalid
docs
f optional The public SDK encodes new-party and new-session states as t or f. vendor.adcanvas-csc.param.f.empty
vendor.adcanvas-csc.param.f.invalid
docs
l optional The SDK truncates location.href to 1000 JavaScript UTF-16 code units. Supplementary characters occupy two code units. Maximum decoded UTF-16 code units: 1000. vendor.adcanvas-csc.param.l.empty
vendor.adcanvas-csc.param.l.invalid
docs
r optional The SDK copies document.referrer when set; its input string is preserved. docs
u optional Optional SDK event data uses proprietary mincode serialization, not JSON. This value remains opaque. docs
x optional When emitted by this SDK, x is the signed base36 checksum. The checksum computation and the absent-checksum historical branch are not validated. vendor.adcanvas-csc.param.x.empty
vendor.adcanvas-csc.param.x.invalid
docs
method optional The public SDK sends csc-event by assigning an Image src. Complete HTTP capture contract. Native JSON type: string. vendor.adcanvas-csc.http.method.empty
vendor.adcanvas-csc.http.method.invalid
docs

Validate a payload

pixellint validate url "$ARTIFACT" --rulepack vendor/adcanvas-csc

Or paste it into the playground. Same engine, in the browser, nothing sent anywhere.

cargo install pixellint · npm install pixellint