Commit Graph
22 Commits
Author SHA1 Message Date
amitwh f63a678c88 fix(security): strengthen ReDoS denylist in search-in-files
Follow-up to the push-sweep review: the previous UNSAFE_REGEX used
JS bitwise OR (|) between regex literals, accidentally OR-ing the
RegExp objects instead of combining alternatives into one pattern.

Replace with a single RegExp that catches:
- nested quantifiers (a+)+, [a-z]*+
- class + quantifier
- dot-quantifier followed by dot-quantifier
- lookahead / lookbehind (?=, ?!)
- backrefs \1..\9
- alternation + quantifier

Also add MAX_REGEX_LENGTH=200 hard cap. The denylist is still
defense-in-depth — the length, files-traversed, and per-file-byte caps
are the primary defense.
2026-07-23 09:39:08 +05:30
amitwh 5e76d77ece fix(security): harden search-in-files against DoS + path traversal
Address findings from automated security review:

1. Validate rootPath via validatePath/isPathAccessible before recursing,
   matching the pattern used by read-file/write-file.
2. Cap query length at 1024 chars to bound regex compilation cost.
3. Reject regexes matching classic ReDoS shapes (nested quantifiers
   and similar) before invoking RegExp.
4. Use realpathSync to resolve symlinks and verify containment under
   rootPath; drop symlinks that point outside the search root.
5. Cap total files traversed at 10000, in addition to existing
   1000-result and 2MB-per-file caps.

Add regression tests for each guard.
2026-07-23 09:34:57 +05:30
amitwh 6da2ba7cc7 fix(ipc): crash modal reads wrapper, search wired to real handler
CrashReportModal crashed on dumps.map because ipc.crash.read returns
{ ok, data } and the consumer was assigning the wrapper to state. Now
unwraps .data and falls back to [] on error.

ipc.file.search was miswired to ipc.file.pickFile — clicking 'Search'
popped a file picker instead of searching. Add real 'search-in-files'
handler in src/main/files/search-in-files.js with regex support,
case-sensitivity toggle, .git/node_modules/dist skip, 2MB file cap, and
1000-result limit. Wire preload bridge + TS declaration + allowlist.

Also:
- Drop dead ipc.file.open wrapper that was miswired to pickFile
- Rename FileEntry field 'modified' to 'modifiedAt' (number) so the
  IPC payload matches the declared type
- Update CrashReportModal tests to use the safeCall envelope shape
2026-07-23 09:34:57 +05:30
amitwh f1f8a16a79 fix: list-directory returns flat array, drop defensive fallback
The list-directory handler returned { path, entries } while the
renderer typed result.data as FileEntry[]; the file-store had to fall
back to raw.entries via Array.isArray. Extract the entries builder into
src/main/files/list-directory.js so it can be unit-tested, return a
plain array, and skip entries that can't be stat'd (broken symlinks,
permission errors) instead of throwing.

Also tighten jest config so dist/*.snap electron-builder artifacts are
not matched as test suites.
2026-07-23 09:34:57 +05:30
amitwh 772a791d9a fix(git): git-status IPC returns a flat array, not wrapped object
GitOperations.getStatus returns { files: [...] } but the renderer's
ipc.file.gitStatus type declares Array<...> and calls result.data.map().
The mismatch made GitStatusPanel.tsx throw 'n.map is not a function'
on mount, which blanked the entire React tree.

Unwrap result.files in the IPC handler so it returns the array the
renderer expects. Add tests covering the success, empty, and non-git
branches so this regression cannot recur.

Refs: blank-screen-on-md-open
2026-07-23 09:34:57 +05:30
amitwh b2ad8b8326 fix(security): address supply-chain + resource-leak findings
- PdfFontHeader: use mkdtempSync for exclusive temp dir; caller unlinks
  after pandoc consumes (cleanup wired into exportWithPandoc callback)
- download-tools: pin FiraCode to immutable release v6.2 with SHA-256
  digests verified before atomic rename; refuse download on mismatch
- Vendor missing FiraCode-Bold.ttf + JetBrainsMono-Regular.ttf
2026-07-23 09:34:57 +05:30
amitwh 65dfdfb307 feat(monospace): add get/set IPC handlers with safe validation 2026-07-23 09:34:57 +05:30
amitwh f1c3aaa0ef feat(monospace): build CSS with embedded woff2 base64 2026-07-23 09:34:57 +05:30
amitwh 0c37a8ca2d feat(monospace): EPUB embed-font helper + manifest patcher 2026-07-23 09:34:57 +05:30
amitwh 992c6b72d6 feat(monospace): embed TTF into pandoc-generated DOCX 2026-07-23 09:34:57 +05:30
amitwh 001c9463e3 feat(monospace): add xelatex fontspec header builder 2026-07-23 09:34:57 +05:30
amitwh 3602bc35a7 feat(monospace): add path resolver for bundled TTF assets 2026-07-23 09:34:57 +05:30
amitwh 14b5a38a5a feat(monospace): add settings schema with safe defaults 2026-07-23 09:34:57 +05:30
amitwh 6b564a4569 style: run prettier formatter over src and tests 2026-06-11 20:46:00 +05:30
amitwh e25a5e1d75 fix(migration): normalize legacy theme values under v5 marker
Two related bugs surfaced during end-to-end verification:

1. The 'isAlreadyV5' short-circuit in both the main-side and renderer-side
   v4-to-v5 transforms returned the persisted object as-is when a
   migration.version=5 marker was present. A previously-shipped v4 build
   had written theme: 'ayu-light' (and similar) under the v5 marker;
   the transform trusted the marker and passed the invalid theme through,
   which then failed the renderer's zod schema on every launch and
   reset user settings to defaults.

   Fix: in both transforms, when isAlreadyV5 matches, normalize theme
   against the v5 enum (light/dark/system) and validate the full result
   with the v5 schema before returning. Out-of-range values are replaced
   with the v5 default ('system').

2. The renderer's settings-store onRehydrateStorage callback called
   useSettingsStore.setState() to reset the store on validation failure.
   At that moment the store is still being constructed, and setState
   could hit a TDZ ReferenceError (the one we already wrapped in a
   try/catch in v5.0.0, which only hid the symptom).

   Fix: return the normalized state object from onRehydrateStorage
   instead. Zustand's persist middleware applies the returned value
   *after* construction completes, so there is no TDZ.

Tests: 334 vitest + 208 jest = 542 passing.
E2E: 12/12 verify-features.mjs steps green; no console errors.

Amit Haridas
2026-06-08 07:45:06 +05:30
amitwh c5d4b113bd fix(polish): address 3 review blockers + 1 security issue
1. ThemeSettings: change 'auto' radio value to 'system' to match
   the v5 settingsSchema enum. Storing 'auto' silently wipes all
   settings on next launch.
2. UpdateBanner: render an 'available' branch so users see a CTA
   when a new version is detected (the store already had this state,
   but the banner was silent). Added a test.
3. feed-config: remove the unused resolveFeedUrl / FEEDS exports.
   feedConfigFor is the actual implementation used by the IPC
   handler. Updated tests to match.
4. main/index.js: tighten app:open-external regex to https:// only.
2026-06-08 07:35:54 +05:30
amitwh 6df1389cc8 fix(updater): dispatch setFeedURL by provider instead of raw url 2026-06-08 07:11:28 +05:30
amitwh aeadde5f40 fix(migration): handle already-v5 settings and ensure 'failed' branch writes v5 marker 2026-06-08 07:02:45 +05:30
amitwh c62070304f feat(migration): add v4-to-v5 settings migration runner with backup 2026-06-08 06:16:17 +05:30
amitwh 9f4bfbdfee feat(crash): add CrashWriter for local crash dumps (cap 20, prune oldest) 2026-06-08 06:14:02 +05:30
amitwh 2e41b59da5 feat(updater): add UpdaterService wrapping electron-updater lifecycle 2026-06-08 06:12:04 +05:30
amitwh 57c8f92f42 feat(updater): add feed-config to map channel setting to feed URL 2026-06-08 06:10:06 +05:30